Packages changed: Mesa Mesa-drivers MicroOS-release (20250909 -> 20250910) ffmpegthumbs gpg2 (2.5.11 -> 2.5.12) libXScrnSaver (1.2.4 -> 1.2.5) libplacebo5 net-tools polkit-default-privs (1550+20250721.f1b71a3 -> 1550+20250904.99b438e) qt6-webengine sdbootutil (1+git20250903.f5a076b -> 1+git20250909.8b2878e) selinux-policy (20250902 -> 20250909) tiff tpm2.0-abrmd util-linux util-linux-systemd === Details === ==== Mesa ==== Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - baselibs.conf: let Mesa-32bit obsolete Mesa-gallium-32bit ==== Mesa-drivers ==== Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - baselibs.conf: let Mesa-32bit obsolete Mesa-gallium-32bit ==== MicroOS-release ==== Version update (20250909 -> 20250910) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== ffmpegthumbs ==== - Add patch: * ffmpegthumbs-ffmpeg8.patch ==== gpg2 ==== Version update (2.5.11 -> 2.5.12) - Update to 2.5.12: * gpg: New options --[no-]auto-key-upload * gpg: Keys send to an LDAP server are now first updated from that server. New keyserver option "no-update-before-send" to disable this feature * gpg: Disable default compression for 7z compressed input * gpg: Fix a regression with composite PQC and ECC algos * gpg: Fix the list of possible algos for --edit-key:addkey * gpg: Allow to select the Kyber variants with --edit-key:addkey * gpg: Avoid a second Pinentry pop-up for a configured ADSK during key generation * gpg: Change the ADSK key binding time to use the current time * gpgsm: Add option --no-qes-note and new trustlist flag "noconsent" * agent: Enable "relax" in the trustlist by default and add flag "norelax" * scd:openpgp: Support Yubikey attestation generation * gpgtar: Fix regression in end-of-archive detection ==== libXScrnSaver ==== Version update (1.2.4 -> 1.2.5) - Update to version 1.2.5 * Remove "All rights reserved" from Oracle copyright notices * configure: Use LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL * meson: Add option to build with meson * Improve man page formatting - switch to meson ==== libplacebo5 ==== - Disabled tests and dropped plplay5 package, as this package only exists to provide libplacebo264 for VLC. We don't need the demos or run tests. ==== net-tools ==== - Drop 0002-Do-not-warn-about-interface-socket-not-binded.patch. It worked around a net-tools-1.60 specific problem, that does not happen in net-tools-2.10. It is more harmful than useful, as it can hide real problems. (bsc#430864#c15, https://github.com/ecki/net-tools/issues/32#issuecomment-3265471116). ==== polkit-default-privs ==== Version update (1550+20250721.f1b71a3 -> 1550+20250904.99b438e) - Update to version 1550+20250904.99b438e: * profiles: add mutter backlight-helper (bsc#1248851) * Add CODEOWNERS file * Pin actions to specific version SHA * Add explicit read-only permission on repo contents * profiles: drop no longer used deepin whitelistings * build(deps): bump actions/checkout from 4 to 5 ==== qt6-webengine ==== Subpackages: libQt6WebEngineCore6 libQt6WebEngineQuick6 libQt6WebEngineWidgets6 qt6-webengine-imports - Add patch: * QtWebEngine_6.9.2_QTBUG-139424.patch (QTBUG-139424, boo#1249354) ==== sdbootutil ==== Version update (1+git20250903.f5a076b -> 1+git20250909.8b2878e) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20250909.8b2878e: * Check KEY for LUKS2 password ==== selinux-policy ==== Version update (20250902 -> 20250909) Subpackages: selinux-policy-targeted - Update to version 20250909 (bsc#1249209): * Allow gdm create /etc/.pwd.lock with a file transition * Allow gdm bind a socket in the /run/systemd/userdbd directory * Allow nsswitch_domain connect to xdm over a unix domain socket - selinux-policy-devel needs to own /usr/share/selinux/devel/include/distributed otherwise packages that follow this guideline can not build without owning the directory themselves: https://fedoraproject.org/wiki/SELinux/IndependentPolicy#Using_custom_interfaces - Update to version 20250904: * Allow systemd homed getattr all tmpfs files (bsc#1240883) * Allow systemd (PID 1) create lastlog entries * Allow systemd_homework_t transition pid files to lvm_var_run_t (bsc#1240883) * Allow gnome-remote-desktop speak with tabrmd over dbus (bsc#1244573) * Allow nm-dispatcher iscsi and sendmail plugins get pidfs attributes * Allow systemd-oomd watch tmpfs dirs * Allow chronyc the setgid and setuid capabilities ==== tiff ==== - security update: * CVE-2025-8961 [bsc#1248117] Fix segmentation fault via main function of tiffcrop utility + tiff-CVE-2025-8961.patch ==== tpm2.0-abrmd ==== Subpackages: libtss2-tcti-tabrmd0 tpm2.0-abrmd-selinux - also package new /usr/share/selinux/devel/include/distributed directory to fix build error. - Move tabrmd interface file from /usr/share/selinux/devel/include/contrib/tabrmd.if to /usr/share/selinux/devel/include/distributed/tabrmd.if This is necessary to allow upstream drop-in interface replacements: https://github.com/fedora-selinux/selinux-policy/blob/rawhide/policy/modules/contrib/tabrmd.if ==== util-linux ==== Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - Implement escape code for printing of ssh host keys in agetty issue file (util-linux-agetty-ssh-host-keys.patch. - Include fixes from https://github.com/util-linux/util-linux/pull/3649 (jsc#PED-8734, util-linux-lib-netlink.patch, util-linux-agetty-netlink.patch). ==== util-linux-systemd ==== Subpackages: lastlog2 liblastlog2-2 - Implement escape code for printing of ssh host keys in agetty issue file (util-linux-agetty-ssh-host-keys.patch. - Include fixes from https://github.com/util-linux/util-linux/pull/3649 (jsc#PED-8734, util-linux-lib-netlink.patch, util-linux-agetty-netlink.patch).