Please note that this mail was generated by a script.
The described changes are computed based on the aarch64 DVD.
The full online repo contains too many changes to be listed here.

Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=3&version=Tumbleweed&build=20250910

Please do not reply to this email to report issues, rather file a bug
on bugzilla.opensuse.org. For more information on filing bugs please
see https://en.opensuse.org/openSUSE:Submitting_bug_reports

Packages changed:
  Mesa
  Mesa-drivers
  ffmpegthumbs
  gpg2 (2.5.11 -> 2.5.12)
  libXScrnSaver (1.2.4 -> 1.2.5)
  libXres (1.2.2 -> 1.2.3)
  libplacebo5
  nbd (3.25 -> 3.26.1)
  net-tools
  openSUSE-release (20250909 -> 20250910)
  polkit-default-privs (1550+20250721.f1b71a3 -> 1550+20250904.99b438e)
  qt6-webengine
  sdbootutil (1+git20250903.f5a076b -> 1+git20250909.8b2878e)
  selinux-policy (20250902 -> 20250909)
  tiff
  tpm2.0-abrmd
  tuned (2.25.1.0+git.889387b -> 2.26.0.0+git.181472a)
  util-linux
  util-linux-systemd

=== Details ===

==== Mesa ====
Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1

- baselibs.conf: let Mesa-32bit obsolete Mesa-gallium-32bit

==== Mesa-drivers ====
Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp

- baselibs.conf: let Mesa-32bit obsolete Mesa-gallium-32bit

==== ffmpegthumbs ====

- Add patch:
  * ffmpegthumbs-ffmpeg8.patch

==== gpg2 ====
Version update (2.5.11 -> 2.5.12)
Subpackages: dirmngr

- Update to 2.5.12:
  * gpg: New options --[no-]auto-key-upload
  * gpg: Keys send to an LDAP server are now first updated from that
    server.  New keyserver option "no-update-before-send" to disable
    this feature
  * gpg: Disable default compression for 7z compressed input
  * gpg: Fix a regression with composite PQC and ECC algos
  * gpg: Fix the list of possible algos for --edit-key:addkey
  * gpg: Allow to select the Kyber variants with --edit-key:addkey
  * gpg: Avoid a second Pinentry pop-up for a configured ADSK during
    key generation
  * gpg: Change the ADSK key binding time to use the current time
  * gpgsm: Add option --no-qes-note and new trustlist flag
    "noconsent"
  * agent: Enable "relax" in the trustlist by default and add flag
    "norelax"
  * scd:openpgp: Support Yubikey attestation generation
  * gpgtar: Fix regression in end-of-archive detection

==== libXScrnSaver ====
Version update (1.2.4 -> 1.2.5)

- Update to version 1.2.5
  * Remove "All rights reserved" from Oracle copyright notices
  * configure: Use LT_INIT from libtool 2 instead of deprecated
    AC_PROG_LIBTOOL
  * meson: Add option to build with meson
  * Improve man page formatting
- switch to meson

==== libXres ====
Version update (1.2.2 -> 1.2.3)

- Update to version 1.2.3
  * Remove "All rights reserved" from Oracle copyright notices
  * configure: Use LT_INIT from libtool 2 instead of deprecated
    AC_PROG_LIBTOOL
  * configure: add xproto to pkg-config dependencies list
  * xres.pc: list minimum version of 1.6 for libX11 dependency
  * meson: Add option to build with meson
  * Improve man page formatting
- switch to meson

==== libplacebo5 ====

- Disabled tests and dropped plplay5 package, as this package only
  exists to provide libplacebo264 for VLC. We don't need the demos
  or run tests.

==== nbd ====
Version update (3.25 -> 3.26.1)

- version update to 3.26.1
  * fix missing -F short-option for certfile by @panarom in #151
  * add option for gnutls priority string by @panarom in #152
  * fix port setting from nbdtab by @felixonmars in #154
  * Fix for a synchronization bug in the handling of errors in NBD_OPT_GO by 
@ebblake
  * Various fixes for issues found by a number of static analyzers, by Łukasz 
Stelmach and the Tizen team
  * fix the building of man pages
- deleted patches
  - 0001_fix_setgroup.patch (upstreamed)
- added patches
  
https://github.com/NetworkBlockDevice/nbd/commit/f8d7d3dbf1ef2ef84c92fe375ebc8674a79e25c2
  + nbd-forgotten-sh.tmpl.patch

==== net-tools ====

- Drop 0002-Do-not-warn-about-interface-socket-not-binded.patch. It
  worked around a net-tools-1.60 specific problem, that does not
  happen in net-tools-2.10. It is more harmful than useful, as it
  can hide real problems. (bsc#430864#c15,
  https://github.com/ecki/net-tools/issues/32#issuecomment-3265471116).

==== openSUSE-release ====
Version update (20250909 -> 20250910)
Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd

- automatically generated by openSUSE-release-tools/pkglistgen

==== polkit-default-privs ====
Version update (1550+20250721.f1b71a3 -> 1550+20250904.99b438e)

- Update to version 1550+20250904.99b438e:
  * profiles: add mutter backlight-helper (bsc#1248851)
  * Add CODEOWNERS file
  * Pin actions to specific version SHA
  * Add explicit read-only permission on repo contents
  * profiles: drop no longer used deepin whitelistings
  * build(deps): bump actions/checkout from 4 to 5

==== qt6-webengine ====
Subpackages: libQt6WebEngineCore6 libQt6WebEngineQuick6 libQt6WebEngineWidgets6 
qt6-webengine-imports

- Add patch:
  * QtWebEngine_6.9.2_QTBUG-139424.patch (QTBUG-139424, boo#1249354)

==== sdbootutil ====
Version update (1+git20250903.f5a076b -> 1+git20250909.8b2878e)
Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper

- Update to version 1+git20250909.8b2878e:
  * Check KEY for LUKS2 password

==== selinux-policy ====
Version update (20250902 -> 20250909)
Subpackages: selinux-policy-targeted

- Update to version 20250909 (bsc#1249209):
  * Allow gdm create /etc/.pwd.lock with a file transition
  * Allow gdm bind a socket in the /run/systemd/userdbd directory
  * Allow nsswitch_domain connect to xdm over a unix domain socket
- selinux-policy-devel needs to own /usr/share/selinux/devel/include/distributed
  otherwise packages that follow this guideline can not build without owning
  the directory themselves:
  
https://fedoraproject.org/wiki/SELinux/IndependentPolicy#Using_custom_interfaces
- Update to version 20250904:
  * Allow systemd homed getattr all tmpfs files (bsc#1240883)
  * Allow systemd (PID 1) create lastlog entries
  * Allow systemd_homework_t transition pid files to lvm_var_run_t (bsc#1240883)
  * Allow gnome-remote-desktop speak with tabrmd over dbus (bsc#1244573)
  * Allow nm-dispatcher iscsi and sendmail plugins get pidfs attributes
  * Allow systemd-oomd watch tmpfs dirs
  * Allow chronyc the setgid and setuid capabilities

==== tiff ====

- security update:
  * CVE-2025-8961 [bsc#1248117]
    Fix segmentation fault via main function of tiffcrop utility
    + tiff-CVE-2025-8961.patch

==== tpm2.0-abrmd ====
Subpackages: libtss2-tcti-tabrmd0 tpm2.0-abrmd-selinux

- also package new /usr/share/selinux/devel/include/distributed directory to
  fix build error.
- Move tabrmd interface file from 
/usr/share/selinux/devel/include/contrib/tabrmd.if
  to /usr/share/selinux/devel/include/distributed/tabrmd.if
  This is necessary to allow upstream drop-in interface replacements:
  
https://github.com/fedora-selinux/selinux-policy/blob/rawhide/policy/modules/contrib/tabrmd.if

==== tuned ====
Version update (2.25.1.0+git.889387b -> 2.26.0.0+git.181472a)

- Update to version 2.26.0.0+git.181472a:
  * new release (2.26.0)
  * new release (2.26.0-rc.1)
  * fix: add no_turbo option in profiles where boost is used
  * If plugin isn't supported, log details why it isn't supported
  * Fixed instance priority inheritance
  * functions: Make calc_isolated_cores return CPU ranges
  * Allow overriding the no_turbo setting
  * udev: fix possible traceback in device matcher
  * vm: Deprecate dirty_ratio in favour of dirty_bytes with %
  * tuned-ppd: Pin virtual files in memory for inotify
  * tuned-ppd: Fix indentation
  * tuned-ppd: Fix inotify watch for performance degradation
  * Dockerfile: New to build on a bootc image
  * bootloader: Remove previously appended rpm-ostree kargs
  * bootloader: Simplify tuning of rpm-ostree kargs
  * udev-settle: obey udev buffer size and handle possible tracebacks
  * plugins: Support MMC devices
  * CI: build and test for c10s
  * tests/beakerlib: remove old API call.
  * spec: minor spec cleanup and enabled doc install on RHEL
  * tuned-main.conf: added startup_udev_settle_wait option
  * consts: fixed whitespaces
  * Re-raise daemon init exception in no-daemon mode
  * scsi: Do not set ALPM on external SATA ports
  * realtime: Disable appropriate P-State drivers
  * beakerlib: Use ncat explicitly instead of nc
  * hotplug: fixed device remove race condition
  * perf: dropped from irqbalance and improved detection in scheduler
  * variables: Add an option to prepend child variables before parent ones
  * ppd: Enable sysfs_acpi_monitor by default
  * GUI: Fix the profile deleter script
  * functions: Silence errors if module kvm_intel does not exist
  * ppd: Rename thinkpad_function_keys as sysfs_acpi_monitor
  * network_latency: Set non-zero rcutree.nohz_full_patience_delay
  * profiles: use `med_power_with_dipm` for SATA ALPM Using `min_power` can 
lead to data loss, and `med_power_with_dipm` delivers similar power savings 
without the chance of data loss. [1]
  * plugins: document `med_power_with_dipm` SATA ALPM option The use of 
`min_power` can lead to data corruption[1] and has been replaced in the 
documentation, and an example using `medium_power` was updated to use 
`med_power_with_dipm` (the kernel default[2] with better better power savings 
than `medium_power`).

==== util-linux ====
Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1

- Implement escape code for printing of ssh host keys in agetty
  issue file (util-linux-agetty-ssh-host-keys.patch.
- Include fixes from
  https://github.com/util-linux/util-linux/pull/3649 (jsc#PED-8734,
  util-linux-lib-netlink.patch, util-linux-agetty-netlink.patch).

==== util-linux-systemd ====
Subpackages: lastlog2 liblastlog2-2

- Implement escape code for printing of ssh host keys in agetty
  issue file (util-linux-agetty-ssh-host-keys.patch.
- Include fixes from
  https://github.com/util-linux/util-linux/pull/3649 (jsc#PED-8734,
  util-linux-lib-netlink.patch, util-linux-agetty-netlink.patch).


Reply via email to