Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package mozilla-nss for openSUSE:Factory checked in at 2026-09-21 12:00:06 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old) and /work/SRC/openSUSE:Factory/.mozilla-nss.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "mozilla-nss" Mon Sep 21 12:00:06 2026 rev:246 rq:1379125 version:3.128 Changes: -------- --- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes 2026-09-04 12:37:28.992416186 +0200 +++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.383539/mozilla-nss.changes 2026-09-21 12:00:09.467535681 +0200 @@ -1,0 +2,60 @@ +Tue Sep 15 20:37:31 UTC 2026 - Wolfgang Rosenauer <[email protected]> + +- update to NSS 3.128 + * bmo#2063360 - Rejoin the table cells the conversion wrapped mid-construct + * bmo#2063360 - Generate heading anchors and stop the headings + linking to themselves + * bmo#2063360 - Unlink the self-linking headings in the release notes + * bmo#2063360 - Point documentation cross-references at the dashed anchors + * bmo#2063360 - Fix doc-lint in the release process + * bmo#2066375 - Make fuzz tasks selectable with try syntax + * bmo#2066375 - Build Cryptofuzz in its own CI task + * bmo#2066604 - fix EC public key encoding in sftk_PutPubKey + * bmo#2066183 - set CKA_ID on imported private keys + * bmo#2017925 - Hash prfs need to be evaluated for indicators + * bmo#2066327 - rename libcrux gyp target + * bmo#2066415 - Update BoGo tests to disable ML_DSA Default test + * bmo#2065354 - unify the two clang-format docker images + * bmo#2056265 - -trust-cert for TLS BoGo tests + * bmo#2056235 - DTLS1.2/1.3 - silently discard invalid records + * bmo#2052273 - Adding -trust-cert support for BoGo DTLS tests + * bmo#2063443 - nullify dangling pointers in libssl, pk11wrap, and softoken + * bmo#2027768 - Fix build failure due to missing gcm stubs if on big endian + * bmo#2065354 - clang-format everything + * bmo#2065354 - Update clang-format version to 22 + * bmo#2054818 - make mach try work with git-cinnabar checkouts + * bmo#2054696 - avoid integer overflow in PK11SDR_EncryptWithMechanism + * bmo#2056778 - fix slot over-release in PK11_FindCertFromDERCertItem + * bmo#2056789 - fix missing BAD_PARAM_CAST in NSC_DeriveKey + CKM_DES3_CBC_ENCRYPT_DATA branch + * bmo#2064946 - additional ML-DSA ssl gtests + * bmo#2064644 - ml_dsat.h: portable comments should use block comment style + * bmo#1983320 - ml-dsa tls tests + * bmo#2056787 - hold handshake locks longer in SSL_ResetHandshake + * bmo#1983320 - ML-DSA tests for Sign/Verify, certificates and pkcs12 + * bmo#2056786 - take smime profile lock while updating profile data + * bmo#2062824 - add defensive null checks in PK11_Encapsulate and + PK11_Decapsulate + * bmo#2062822 - nulled slot in pk11_loadPrivKeyWithFlags leads to token + object leak + * bmo#2062802 - handle ML-KEM in stfk_CopyTokenPrivateKey and + stfk_CopyTokenPublicKey + * bmo#2062450 - Allow unknown hashAlg with ML-DSA in VFY_VerifyDataDirect + * bmo#2062379 - additional ML-KEM tests + * bmo#2062375 - handle unknown ML-KEM parameter sets in + PK11_ExtractPublicKey + * bmo#2062373 - missing CKP_NSS_ML_KEM_768 branches in seckey helper + functions + * bmo#2062372 - remove unused sftk_kyber_AllocCiphertextItem function + * bmo#2060302 - additional ML-DSA tests + * bmo#2060358 - add wycheproof tests for ML-KEM and ML-DSA + * bmo#2060302 - vendor libcrux ML-DSA and enable the ML-DSA freebl backend + * bmo#2060301 - bump libcrux and re-vendor ML-KEM from the combined + C extraction + * bmo#2027352 - validate IV length for CKM_RC2_CBC in + pk11_ParamFromIVWithLen + * bmo#1983320 - ml-dsa tls patch + * bmo#2056775 - protect nssPKIObject.cryptoContext with a lock +- rebase add-relro-linker-option.patch + +------------------------------------------------------------------- Old: ---- nss-3.127.tar.gz New: ---- nss-3.128.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ mozilla-nss.spec ++++++ --- /var/tmp/diff_new_pack.Tbwr4f/_old 2026-09-21 12:00:16.621835731 +0200 +++ /var/tmp/diff_new_pack.Tbwr4f/_new 2026-09-21 12:00:16.627835982 +0200 @@ -40,9 +40,9 @@ %define origname mozilla-nss Name: %{origname}%{psuffix} -Version: 3.127 +Version: 3.128 Release: 0 -%define underscore_version 3_127 +%define underscore_version 3_128 Summary: Network Security Services License: MPL-2.0 Group: System/Libraries ++++++ add-relro-linker-option.patch ++++++ --- /var/tmp/diff_new_pack.Tbwr4f/_old 2026-09-21 12:00:16.914848019 +0200 +++ /var/tmp/diff_new_pack.Tbwr4f/_new 2026-09-21 12:00:16.923848397 +0200 @@ -5,14 +5,14 @@ @@ -184,6 +184,12 @@ endif endif endif - + +# harden DSOs/executables a bit against exploits +ifeq (2.6,$(firstword $(sort 2.6 $(OS_RELEASE)))) +DSO_LDOPTS+=-Wl,-z,relro +LDFLAGS += -Wl,-z,relro +endif + - USE_SYSTEM_ZLIB = 1 - ZLIB_LIBS = -lz - + # Test toolchain for endianness and set LITTLE_ENDIAN variable accordingly + ENDIANNESS := $(shell echo | $(CC) -dM -E - | grep __BYTE_ORDER__) + ifeq ($(findstring __ORDER_LITTLE_ENDIAN__,$(ENDIANNESS)),__ORDER_LITTLE_ENDIAN__) ++++++ nss-3.127.tar.gz -> nss-3.128.tar.gz ++++++ /work/SRC/openSUSE:Factory/mozilla-nss/nss-3.127.tar.gz /work/SRC/openSUSE:Factory/.mozilla-nss.new.383539/nss-3.128.tar.gz differ: char 5, line 1
