Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package netty for openSUSE:Factory checked 
in at 2026-09-24 23:00:00
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/netty (Old)
 and      /work/SRC/openSUSE:Factory/.netty.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "netty"

Thu Sep 24 23:00:00 2026 rev:17 rq:1380169 version:4.1.138

Changes:
--------
--- /work/SRC/openSUSE:Factory/netty/netty.changes      2026-07-28 
18:07:45.253217908 +0200
+++ /work/SRC/openSUSE:Factory/.netty.new.383539/netty.changes  2026-09-24 
23:02:06.852906665 +0200
@@ -1,0 +2,169 @@
+Thu Sep 24 09:36:57 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to upstream version 4.1.138
+  * Security fixes:
+    + CVE-2026-93488, bsc#1282084: unbounded resource usage in
+      io.netty:netty-codec-http (SPDY)
+    + CVE-2026-93491, bsc#1282085: unbounded resource usage in
+      io.netty:netty-codec-http (HTTP/1.1)
+    + CVE-2026-93492, bsc#1282132: denial of service vector in
+      io.netty:netty-codec-http2
+    + CVE-2026-93493, bsc#1281431: improper certificate validation
+      in io.netty:netty-handler-ssl-ocsp
+    + CVE-2026-93494, bsc#1282506: memory leak in io.netty
+      :netty-codec-stomp
+    + CVE-2026-93558, bsc#1282140: unbounded resource usage in
+      io.netty:netty-codec-http
+    + CVE-2026-93560, bsc#1282141: denial of service vector in
+      io.netty:netty-codec-stomp
+    + CVE-2026-89044, bsc#1280048: parser desync/response smuggling
+      in io.netty:netty-codec-memcache
+    + CVE-2026-93562, bsc#1282362: improper header validation in
+      io.netty:netty-codec-http
+    + CVE-2026-93563, bsc#1281432: unbounded resource usage in
+      io.netty:netty-codec-smtp
+    + CVE-2026-93564, bsc#1282363: memory leak in
+      io.netty:netty-codec-haproxy
+    + CVE-2026-93565, bsc#1282364: request smuggling in
+      io.netty:netty-codec-http (RTSP)
+    + CVE-2026-93566, bsc#1282366: request smuggling in
+      io.netty:netty-codec-http (HTTP/1)
+    + CVE-2026-93567, bsc#1282367: improper header validation in
+      io.netty:netty-codec-http2
+    + CVE-2026-93568, bsc#1282370: improper header validation in
+      io.netty:netty-codec-http2
+    + CVE-2026-93569, bsc#1282372: improper header validation in
+      io.netty:netty-codec-http2
+    + CVE-2026-93572, bsc#1281433: unbounded resource usage in
+      io.netty:netty-codec-redis
+    + CVE-2026-93573, bsc#1282373: improper header validation in
+      io.netty:netty-codec-http (HTTP/1.1)
+    + CVE-2026-93574, bsc#1282374: request smuggling vector in
+      io.netty:netty-codec-http (HTTP/1.1)
+    + CVE-2026-93575, bsc#1281434: unbounded resource usage in
+      io.netty:netty-codec-mqtt
+    + CVE-2026-93576, bsc#1282507: improper CRLF neutralization in
+      io.netty:netty-codec-smtp
+    + CVE-2026-93578, bsc#1281435: improper certificate validation
+      in io.netty:netty-handler-ssl-ocsp
+    + CVE-2026-93579, bsc#1282378: improper header validation in
+      io.netty:netty-codec-http2
+  * Other significant changes:
+    + QUIC explicitly requires X509ExtendedTrustManager when
+      hostname verification is enabled
+    + HTTP/2 header value validation is now enabled by default
+    + Use X509ExtendedTrustManager in SSLErrorTest
+    + Validate chunked-must-be-last regardless of HTTP version
+    + Update junit version
+    + Add system property to disable RFC 6761 localhost resolution
+    + Update setup-testlens to v1.9.4 (#17223)
+    + Adjust failsafe plugin version to be in sync with surefire
+      plugin
+    + Release unsent LastHttpContent in HttpChunkedInput
+    + HTTP/2: Release compressors after failed headers writes
+    + HTTP/2: Prevent reentrant flush on writability change
+    + Respect max messages per read in LocalServerChannel (#17255)
+    + HTTP: Preserve encoder state after header encoding failures
+    + Bzip2: Correctly detect overflow during block size bound
+      check (#17261)
+    + HTTP/2: Drain queued frames stranded by a writability change
+      during flush
+    + Add clock skew tolerance to OcspServerCertificateValidator
+    + Extract Bootstrap and ServerBootstrap setup to a common
+      method (#15134)
+    + Release channel when FixedChannelPool acquire is cancelled
+      (#17287)
+    + HTTP: Release content encoder after header mutation failure
+    + Add a script that can download GHSA vulnerability reports
+    + FileRegion: Remove outdated JDK upgrade warning
+    + codec-dns: Fix query OPCODE bit offset and mask
+    + Install patchelf as part of awslc docker image generation
+    + POOL: Close active unhealthy channels on release
+    + Update to use graal 21
+    + Add more logging to CompositeBufferGatheringWriteTest to help
+      diagnose flaky test
+    + Fix graal docker file usage
+    + codec-dns: Report and allow setting full 16-bit EDNS(0) flags
+      field
+    + Kqueue: Continue reading when EOF is received before notify
+      about channel inactivity
+    + Fix MQTT 5 properties length decoding for multi-byte Property
+      Length (4.2 branch)
+    + Increase timeout in test to address flakyness
+    + DatagramUnicastIpv6MappedTest should explicit bind to ipv4
+      address to make test less flaky
+    + Close Channel when connect is cancelled during resolution
+      (#17321)
+    + Channel: Add unit tests for AbstractChannel edge-case
+      failures and buffer releases
+    + Http2: Cleanup child channel method signatures
+    + Update to latest netty-tcnative release
+    + Update to latest netty-jni-util release
+    + Fix JdkZlibDecoder silently truncating highly compressible
+      streams
+    + ByteBufUtil.HexUtil.HEXDUMP_TABLE array length 256*2 is
+      enough
+    + Update to latest netty tcnative version
+- Changes of 4.1.137
+  * Security fixes:
+    + CVE-2026-75596, bsc#1276421: algorithm inefficiency in
+      io.netty:netty-handler
+    + CVE-2026-62380, bsc#1276456: improper NUL byte neutralization
+      in io.netty:netty-codec-socks
+    + CVE-2026-75595, bsc#1276420: SNI bypass in io.netty
+      :netty-handler
+    + CVE-2026-59902, bsc#1275501: memory exhaustion in
+      io.netty:netty-transport-sctp
+    + CVE-2026-59903, bsc#1275500: cache poisoning & info disclosure
+      in io.netty:netty-codec-http
+    + CVE-2026-76816, bsc#1277243: validation bypass in
+      io.netty:netty-codec-mqtt
+    + CVE-2026-62243, bsc#1276455: improper hostname verification in
+      io.netty:netty-handler
+  * Other significant changes:
+    + AsciiString.cached(String) should sanitize the provided
+      String (#13749)
+    + AsciiString.cached(String) should sanitize the provided
+      String (#13749) (#17007)
+    + Fix AsciiString.cached(String) performance regression
+      (#17074)
+    + SslHandler: Fix possible buffer leak when an OOME is thrown
+      during allocation
+    + Fix AsciiString.cached(String) performance regression
+      (#17074)
+    + Add HttpContentCompressor constructor with ability to specify
+      desired maxPipelineDepth
+    + Fix AdaptiveByteBuf._setLongLE calling checked setLongLE
+    + Reject negative maxOrder in PooledByteBufAllocator
+    + Snappy: Guard decoder against invalid chunk lengths
+    + Backport #16079 and #17114
+    + Use safe decompressor in Lz4FrameDecoder
+    + Configure TestLens for the PR builds
+    + Fix maxAllocation for brotli-encoded content in
+      HttpContentDecompressor (#17037)
+    + Propagate the CI envionment variables through to the docker
+      builds (#17138)
+    + fix(mqtt): drop UNSUBACK reason codes for MQTT 3.x encoding
+    + Fix buddy cache evicting chunks with live buffers (#17154)
+    + Avoid classloader leak via GlobalEventExecutor
+      terminationFuture failure
+    + HttpObjectEncoder / DefaultHttp2FrameWriter: fix buffer leak
+      when a Throwable is thrown during header encoding
+    + BrotliEncoder: Prevent duplicate close scheduling (#17175)
+    + Update compress-lzf to 1.2.1
+    + Do not write WebSocket handshake response to the tail of the
+      pipeline (#17192)
+    + HttpServerCodec: do not consume the method queue for 1xx
+      interim responses (#17182)
+    + Adaptive allocator backports
+    + Weakly reference engines from the OpenSSL engine map (#17199)
+    + Add .editorconfig to enforce consistent coding style
+    + Update surefire plugin to latest version (#17210)
+    + Update to latest netty-tcnative release (#17056)
+    + Merge changes from forks (#17213)
+- Modified patches:
+  * 0001-Remove-optional-dep-Blockhound.patch
+  * 0004-Disable-Brotli-and-ZStd-compression.patch
+    + rebase
+
+-------------------------------------------------------------------

Old:
----
  netty-4.1.136.Final.tar.gz

New:
----
  netty-4.1.138.Final.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ netty.spec ++++++
--- /var/tmp/diff_new_pack.2PEvmT/_old  2026-09-24 23:02:07.682941372 +0200
+++ /var/tmp/diff_new_pack.2PEvmT/_new  2026-09-24 23:02:07.683941414 +0200
@@ -19,7 +19,7 @@
 %global namedreltag .Final
 %global namedversion %{version}%{?namedreltag}
 Name:           netty
-Version:        4.1.136
+Version:        4.1.138
 Release:        0
 Summary:        An asynchronous event-driven network application framework and 
tools for Java
 License:        Apache-2.0

++++++ 0001-Remove-optional-dep-Blockhound.patch ++++++
--- /var/tmp/diff_new_pack.2PEvmT/_old  2026-09-24 23:02:07.702942208 +0200
+++ /var/tmp/diff_new_pack.2PEvmT/_new  2026-09-24 23:02:07.705942334 +0200
@@ -1,4 +1,4 @@
-From 8c1ada1aebcd317efc725094a9602123c945aa49 Mon Sep 17 00:00:00 2001
+From d5606cecbf163f382329702272a9b1095bed95db Mon Sep 17 00:00:00 2001
 From: Mat Booth <[email protected]>
 Date: Mon, 7 Sep 2020 12:17:31 +0100
 Subject: [PATCH 1/4] Remove optional dep Blockhound
@@ -23,7 +23,7 @@
  delete mode 100644 
transport-blockhound-tests/src/test/resources/io/netty/util/internal/mutual_auth_ca.pem
 
 diff --git a/common/pom.xml b/common/pom.xml
-index 3d89945cec..c1c2127a40 100644
+index 5b96ed0977..9482101126 100644
 --- a/common/pom.xml
 +++ b/common/pom.xml
 @@ -89,11 +89,6 @@
@@ -274,7 +274,7 @@
 -io.netty.util.internal.Hidden$NettyBlockHoundIntegration
 \ No newline at end of file
 diff --git a/pom.xml b/pom.xml
-index 7864dd47e8..82a056eeaf 100644
+index f524fe8665..bc9d0f0b43 100644
 --- a/pom.xml
 +++ b/pom.xml
 @@ -909,7 +909,6 @@
@@ -301,7 +301,7 @@
  
 diff --git a/transport-blockhound-tests/pom.xml 
b/transport-blockhound-tests/pom.xml
 deleted file mode 100644
-index 9df065b45b..0000000000
+index 971aa5b7be..0000000000
 --- a/transport-blockhound-tests/pom.xml
 +++ /dev/null
 @@ -1,228 +0,0 @@
@@ -327,7 +327,7 @@
 -  <parent>
 -    <groupId>io.netty</groupId>
 -    <artifactId>netty-parent</artifactId>
--    <version>4.1.136.Final</version>
+-    <version>4.1.138.Final</version>
 -  </parent>
 -
 -  <artifactId>netty-transport-blockhound-tests</artifactId>

++++++ 0004-Disable-Brotli-and-ZStd-compression.patch ++++++
--- /var/tmp/diff_new_pack.2PEvmT/_old  2026-09-24 23:02:07.721943003 +0200
+++ /var/tmp/diff_new_pack.2PEvmT/_new  2026-09-24 23:02:07.724943128 +0200
@@ -1,4 +1,4 @@
-From 5624f7254d8fbc9de088c0751de60ea5b37e2f1b Mon Sep 17 00:00:00 2001
+From de62fe918f089700d6ee68eaf397933300438edf Mon Sep 17 00:00:00 2001
 From: =?UTF-8?q?Fridrich=20=C5=A0trba?= <[email protected]>
 Date: Thu, 30 Mar 2023 13:19:04 +0200
 Subject: [PATCH 4/4] Disable Brotli and ZStd compression
@@ -12,7 +12,7 @@
  5 files changed, 5 insertions(+), 195 deletions(-)
 
 diff --git 
a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java
 
b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java
-index 17f55d3ed5..9bfe5f4cce 100644
+index 3a29123305..c7afed867d 100644
 --- 
a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java
 +++ 
b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java
 @@ -24,9 +24,6 @@ import io.netty.buffer.ByteBuf;
@@ -46,9 +46,9 @@
      private final SnappyOptions snappyOptions;
  
      private final int contentSizeThreshold;
-@@ -174,10 +166,8 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
-      */
-     public HttpContentCompressor(int contentSizeThreshold, 
CompressionOptions... compressionOptions) {
+@@ -194,10 +186,8 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+             CompressionOptions... compressionOptions) {
+         super(maxPipelineDepth);
          this.contentSizeThreshold = 
ObjectUtil.checkPositiveOrZero(contentSizeThreshold, "contentSizeThreshold");
 -        BrotliOptions brotliOptions = null;
          GzipOptions gzipOptions = null;
@@ -57,7 +57,7 @@
          SnappyOptions snappyOptions = null;
          if (compressionOptions == null || compressionOptions.length == 0) {
              compressionOptions = defaultCompressionOptions(
-@@ -192,14 +182,10 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -212,14 +202,10 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
              // This results in the static analysis of native-image 
identifying the instanceof BrotliOptions check
              // and thus BrotliOptions itself as unreachable, enabling 
native-image to link all classes
              // at build time and not complain about the missing Brotli 
classes.
@@ -73,7 +73,7 @@
              } else if (compressionOption instanceof SnappyOptions) {
                  snappyOptions = (SnappyOptions) compressionOption;
              } else {
-@@ -210,8 +196,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -230,8 +216,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
  
          this.gzipOptions = gzipOptions;
          this.deflateOptions = deflateOptions;
@@ -82,7 +82,7 @@
          this.snappyOptions = snappyOptions;
  
          this.factories = new HashMap<String, CompressionEncoderFactory>();
-@@ -222,12 +206,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -242,12 +226,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
          if (this.deflateOptions != null) {
              this.factories.put("deflate", new DeflateEncoderFactory());
          }
@@ -95,7 +95,7 @@
          if (this.snappyOptions != null) {
              this.factories.put("snappy", new SnappyEncoderFactory());
          }
-@@ -239,13 +217,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -259,13 +237,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
          options.add(gzipOptions);
          options.add(deflateOptions);
          options.add(StandardCompressionOptions.snappy());
@@ -109,7 +109,7 @@
          return options.toArray(new CompressionOptions[0]);
      }
  
-@@ -289,8 +260,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -309,8 +280,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
      @SuppressWarnings("FloatingPointEquality")
      protected String determineEncoding(String acceptEncoding) {
          float starQ = -1.0f;
@@ -118,7 +118,7 @@
          float snappyQ = -1.0f;
          float gzipQ = -1.0f;
          float deflateQ = -1.0f;
-@@ -307,10 +276,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -327,10 +296,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
              }
              if (encoding.contains("*")) {
                  starQ = q;
@@ -129,7 +129,7 @@
              } else if (encoding.contains("snappy") && q > snappyQ) {
                  snappyQ = q;
              } else if (encoding.contains("gzip") && q > gzipQ) {
-@@ -319,12 +284,8 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -339,12 +304,8 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
                  deflateQ = q;
              }
          }
@@ -144,7 +144,7 @@
                  return "snappy";
              } else if (gzipQ != -1.0f && gzipQ >= deflateQ && 
this.gzipOptions != null) {
                  return "gzip";
-@@ -333,12 +294,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -353,12 +314,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
              }
          }
          if (starQ > 0.0f) {
@@ -157,7 +157,7 @@
              if (snappyQ == -1.0f && this.snappyOptions != null) {
                  return "snappy";
              }
-@@ -423,31 +378,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
+@@ -443,31 +398,6 @@ public class HttpContentCompressor extends 
HttpContentEncoder {
          }
      }
  
@@ -190,7 +190,7 @@
       * Compression Encoder Factory for create {@link SnappyFrameEncoder}
       * used to compress http content for snappy content encoding
 diff --git 
a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java
 
b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java
-index f6fde48862..475a09ae58 100644
+index 21fbad525d..475a09ae58 100644
 --- 
a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java
 +++ 
b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java
 @@ -15,23 +15,17 @@
@@ -223,7 +223,7 @@
          }
 -        if (Brotli.isAvailable() && 
BR.contentEqualsIgnoreCase(contentEncoding)) {
 -            return new EmbeddedChannel(ctx.channel().id(), 
ctx.channel().metadata().hasDisconnect(),
--              ctx.channel().config(), new BrotliDecoder(maxAllocation));
+-              ctx.channel().config(), 
BrotliDecoder.newDecoderWithMaxAllocation(maxAllocation));
 -        }
 -
          if (SNAPPY.contentEqualsIgnoreCase(contentEncoding)) {

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.2PEvmT/_old  2026-09-24 23:02:07.747944090 +0200
+++ /var/tmp/diff_new_pack.2PEvmT/_new  2026-09-24 23:02:07.751944257 +0200
@@ -1,6 +1,6 @@
-mtime: 1785155627
-commit: 38277e1b198c1f2781864029f18a3b495cba772ffbeca0382c88d84dc9505cfe
+mtime: 1790249469
+commit: 62d22f494960cc68de93b401c8a0a25f74077f1ca35740b4af7c883755e49ca5
 url: https://src.opensuse.org/java-packages/netty
-revision: 38277e1b198c1f2781864029f18a3b495cba772ffbeca0382c88d84dc9505cfe
+revision: 62d22f494960cc68de93b401c8a0a25f74077f1ca35740b4af7c883755e49ca5
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-24 13:31:09.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ netty-4.1.136.Final.tar.gz -> netty-4.1.138.Final.tar.gz ++++++
++++ 15527 lines of diff (skipped)

Reply via email to