Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package netty for openSUSE:Factory checked in at 2026-09-24 23:00:00 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/netty (Old) and /work/SRC/openSUSE:Factory/.netty.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "netty" Thu Sep 24 23:00:00 2026 rev:17 rq:1380169 version:4.1.138 Changes: -------- --- /work/SRC/openSUSE:Factory/netty/netty.changes 2026-07-28 18:07:45.253217908 +0200 +++ /work/SRC/openSUSE:Factory/.netty.new.383539/netty.changes 2026-09-24 23:02:06.852906665 +0200 @@ -1,0 +2,169 @@ +Thu Sep 24 09:36:57 UTC 2026 - Fridrich Strba <[email protected]> + +- Upgrade to upstream version 4.1.138 + * Security fixes: + + CVE-2026-93488, bsc#1282084: unbounded resource usage in + io.netty:netty-codec-http (SPDY) + + CVE-2026-93491, bsc#1282085: unbounded resource usage in + io.netty:netty-codec-http (HTTP/1.1) + + CVE-2026-93492, bsc#1282132: denial of service vector in + io.netty:netty-codec-http2 + + CVE-2026-93493, bsc#1281431: improper certificate validation + in io.netty:netty-handler-ssl-ocsp + + CVE-2026-93494, bsc#1282506: memory leak in io.netty + :netty-codec-stomp + + CVE-2026-93558, bsc#1282140: unbounded resource usage in + io.netty:netty-codec-http + + CVE-2026-93560, bsc#1282141: denial of service vector in + io.netty:netty-codec-stomp + + CVE-2026-89044, bsc#1280048: parser desync/response smuggling + in io.netty:netty-codec-memcache + + CVE-2026-93562, bsc#1282362: improper header validation in + io.netty:netty-codec-http + + CVE-2026-93563, bsc#1281432: unbounded resource usage in + io.netty:netty-codec-smtp + + CVE-2026-93564, bsc#1282363: memory leak in + io.netty:netty-codec-haproxy + + CVE-2026-93565, bsc#1282364: request smuggling in + io.netty:netty-codec-http (RTSP) + + CVE-2026-93566, bsc#1282366: request smuggling in + io.netty:netty-codec-http (HTTP/1) + + CVE-2026-93567, bsc#1282367: improper header validation in + io.netty:netty-codec-http2 + + CVE-2026-93568, bsc#1282370: improper header validation in + io.netty:netty-codec-http2 + + CVE-2026-93569, bsc#1282372: improper header validation in + io.netty:netty-codec-http2 + + CVE-2026-93572, bsc#1281433: unbounded resource usage in + io.netty:netty-codec-redis + + CVE-2026-93573, bsc#1282373: improper header validation in + io.netty:netty-codec-http (HTTP/1.1) + + CVE-2026-93574, bsc#1282374: request smuggling vector in + io.netty:netty-codec-http (HTTP/1.1) + + CVE-2026-93575, bsc#1281434: unbounded resource usage in + io.netty:netty-codec-mqtt + + CVE-2026-93576, bsc#1282507: improper CRLF neutralization in + io.netty:netty-codec-smtp + + CVE-2026-93578, bsc#1281435: improper certificate validation + in io.netty:netty-handler-ssl-ocsp + + CVE-2026-93579, bsc#1282378: improper header validation in + io.netty:netty-codec-http2 + * Other significant changes: + + QUIC explicitly requires X509ExtendedTrustManager when + hostname verification is enabled + + HTTP/2 header value validation is now enabled by default + + Use X509ExtendedTrustManager in SSLErrorTest + + Validate chunked-must-be-last regardless of HTTP version + + Update junit version + + Add system property to disable RFC 6761 localhost resolution + + Update setup-testlens to v1.9.4 (#17223) + + Adjust failsafe plugin version to be in sync with surefire + plugin + + Release unsent LastHttpContent in HttpChunkedInput + + HTTP/2: Release compressors after failed headers writes + + HTTP/2: Prevent reentrant flush on writability change + + Respect max messages per read in LocalServerChannel (#17255) + + HTTP: Preserve encoder state after header encoding failures + + Bzip2: Correctly detect overflow during block size bound + check (#17261) + + HTTP/2: Drain queued frames stranded by a writability change + during flush + + Add clock skew tolerance to OcspServerCertificateValidator + + Extract Bootstrap and ServerBootstrap setup to a common + method (#15134) + + Release channel when FixedChannelPool acquire is cancelled + (#17287) + + HTTP: Release content encoder after header mutation failure + + Add a script that can download GHSA vulnerability reports + + FileRegion: Remove outdated JDK upgrade warning + + codec-dns: Fix query OPCODE bit offset and mask + + Install patchelf as part of awslc docker image generation + + POOL: Close active unhealthy channels on release + + Update to use graal 21 + + Add more logging to CompositeBufferGatheringWriteTest to help + diagnose flaky test + + Fix graal docker file usage + + codec-dns: Report and allow setting full 16-bit EDNS(0) flags + field + + Kqueue: Continue reading when EOF is received before notify + about channel inactivity + + Fix MQTT 5 properties length decoding for multi-byte Property + Length (4.2 branch) + + Increase timeout in test to address flakyness + + DatagramUnicastIpv6MappedTest should explicit bind to ipv4 + address to make test less flaky + + Close Channel when connect is cancelled during resolution + (#17321) + + Channel: Add unit tests for AbstractChannel edge-case + failures and buffer releases + + Http2: Cleanup child channel method signatures + + Update to latest netty-tcnative release + + Update to latest netty-jni-util release + + Fix JdkZlibDecoder silently truncating highly compressible + streams + + ByteBufUtil.HexUtil.HEXDUMP_TABLE array length 256*2 is + enough + + Update to latest netty tcnative version +- Changes of 4.1.137 + * Security fixes: + + CVE-2026-75596, bsc#1276421: algorithm inefficiency in + io.netty:netty-handler + + CVE-2026-62380, bsc#1276456: improper NUL byte neutralization + in io.netty:netty-codec-socks + + CVE-2026-75595, bsc#1276420: SNI bypass in io.netty + :netty-handler + + CVE-2026-59902, bsc#1275501: memory exhaustion in + io.netty:netty-transport-sctp + + CVE-2026-59903, bsc#1275500: cache poisoning & info disclosure + in io.netty:netty-codec-http + + CVE-2026-76816, bsc#1277243: validation bypass in + io.netty:netty-codec-mqtt + + CVE-2026-62243, bsc#1276455: improper hostname verification in + io.netty:netty-handler + * Other significant changes: + + AsciiString.cached(String) should sanitize the provided + String (#13749) + + AsciiString.cached(String) should sanitize the provided + String (#13749) (#17007) + + Fix AsciiString.cached(String) performance regression + (#17074) + + SslHandler: Fix possible buffer leak when an OOME is thrown + during allocation + + Fix AsciiString.cached(String) performance regression + (#17074) + + Add HttpContentCompressor constructor with ability to specify + desired maxPipelineDepth + + Fix AdaptiveByteBuf._setLongLE calling checked setLongLE + + Reject negative maxOrder in PooledByteBufAllocator + + Snappy: Guard decoder against invalid chunk lengths + + Backport #16079 and #17114 + + Use safe decompressor in Lz4FrameDecoder + + Configure TestLens for the PR builds + + Fix maxAllocation for brotli-encoded content in + HttpContentDecompressor (#17037) + + Propagate the CI envionment variables through to the docker + builds (#17138) + + fix(mqtt): drop UNSUBACK reason codes for MQTT 3.x encoding + + Fix buddy cache evicting chunks with live buffers (#17154) + + Avoid classloader leak via GlobalEventExecutor + terminationFuture failure + + HttpObjectEncoder / DefaultHttp2FrameWriter: fix buffer leak + when a Throwable is thrown during header encoding + + BrotliEncoder: Prevent duplicate close scheduling (#17175) + + Update compress-lzf to 1.2.1 + + Do not write WebSocket handshake response to the tail of the + pipeline (#17192) + + HttpServerCodec: do not consume the method queue for 1xx + interim responses (#17182) + + Adaptive allocator backports + + Weakly reference engines from the OpenSSL engine map (#17199) + + Add .editorconfig to enforce consistent coding style + + Update surefire plugin to latest version (#17210) + + Update to latest netty-tcnative release (#17056) + + Merge changes from forks (#17213) +- Modified patches: + * 0001-Remove-optional-dep-Blockhound.patch + * 0004-Disable-Brotli-and-ZStd-compression.patch + + rebase + +------------------------------------------------------------------- Old: ---- netty-4.1.136.Final.tar.gz New: ---- netty-4.1.138.Final.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ netty.spec ++++++ --- /var/tmp/diff_new_pack.2PEvmT/_old 2026-09-24 23:02:07.682941372 +0200 +++ /var/tmp/diff_new_pack.2PEvmT/_new 2026-09-24 23:02:07.683941414 +0200 @@ -19,7 +19,7 @@ %global namedreltag .Final %global namedversion %{version}%{?namedreltag} Name: netty -Version: 4.1.136 +Version: 4.1.138 Release: 0 Summary: An asynchronous event-driven network application framework and tools for Java License: Apache-2.0 ++++++ 0001-Remove-optional-dep-Blockhound.patch ++++++ --- /var/tmp/diff_new_pack.2PEvmT/_old 2026-09-24 23:02:07.702942208 +0200 +++ /var/tmp/diff_new_pack.2PEvmT/_new 2026-09-24 23:02:07.705942334 +0200 @@ -1,4 +1,4 @@ -From 8c1ada1aebcd317efc725094a9602123c945aa49 Mon Sep 17 00:00:00 2001 +From d5606cecbf163f382329702272a9b1095bed95db Mon Sep 17 00:00:00 2001 From: Mat Booth <[email protected]> Date: Mon, 7 Sep 2020 12:17:31 +0100 Subject: [PATCH 1/4] Remove optional dep Blockhound @@ -23,7 +23,7 @@ delete mode 100644 transport-blockhound-tests/src/test/resources/io/netty/util/internal/mutual_auth_ca.pem diff --git a/common/pom.xml b/common/pom.xml -index 3d89945cec..c1c2127a40 100644 +index 5b96ed0977..9482101126 100644 --- a/common/pom.xml +++ b/common/pom.xml @@ -89,11 +89,6 @@ @@ -274,7 +274,7 @@ -io.netty.util.internal.Hidden$NettyBlockHoundIntegration \ No newline at end of file diff --git a/pom.xml b/pom.xml -index 7864dd47e8..82a056eeaf 100644 +index f524fe8665..bc9d0f0b43 100644 --- a/pom.xml +++ b/pom.xml @@ -909,7 +909,6 @@ @@ -301,7 +301,7 @@ diff --git a/transport-blockhound-tests/pom.xml b/transport-blockhound-tests/pom.xml deleted file mode 100644 -index 9df065b45b..0000000000 +index 971aa5b7be..0000000000 --- a/transport-blockhound-tests/pom.xml +++ /dev/null @@ -1,228 +0,0 @@ @@ -327,7 +327,7 @@ - <parent> - <groupId>io.netty</groupId> - <artifactId>netty-parent</artifactId> -- <version>4.1.136.Final</version> +- <version>4.1.138.Final</version> - </parent> - - <artifactId>netty-transport-blockhound-tests</artifactId> ++++++ 0004-Disable-Brotli-and-ZStd-compression.patch ++++++ --- /var/tmp/diff_new_pack.2PEvmT/_old 2026-09-24 23:02:07.721943003 +0200 +++ /var/tmp/diff_new_pack.2PEvmT/_new 2026-09-24 23:02:07.724943128 +0200 @@ -1,4 +1,4 @@ -From 5624f7254d8fbc9de088c0751de60ea5b37e2f1b Mon Sep 17 00:00:00 2001 +From de62fe918f089700d6ee68eaf397933300438edf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fridrich=20=C5=A0trba?= <[email protected]> Date: Thu, 30 Mar 2023 13:19:04 +0200 Subject: [PATCH 4/4] Disable Brotli and ZStd compression @@ -12,7 +12,7 @@ 5 files changed, 5 insertions(+), 195 deletions(-) diff --git a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java -index 17f55d3ed5..9bfe5f4cce 100644 +index 3a29123305..c7afed867d 100644 --- a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java +++ b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentCompressor.java @@ -24,9 +24,6 @@ import io.netty.buffer.ByteBuf; @@ -46,9 +46,9 @@ private final SnappyOptions snappyOptions; private final int contentSizeThreshold; -@@ -174,10 +166,8 @@ public class HttpContentCompressor extends HttpContentEncoder { - */ - public HttpContentCompressor(int contentSizeThreshold, CompressionOptions... compressionOptions) { +@@ -194,10 +186,8 @@ public class HttpContentCompressor extends HttpContentEncoder { + CompressionOptions... compressionOptions) { + super(maxPipelineDepth); this.contentSizeThreshold = ObjectUtil.checkPositiveOrZero(contentSizeThreshold, "contentSizeThreshold"); - BrotliOptions brotliOptions = null; GzipOptions gzipOptions = null; @@ -57,7 +57,7 @@ SnappyOptions snappyOptions = null; if (compressionOptions == null || compressionOptions.length == 0) { compressionOptions = defaultCompressionOptions( -@@ -192,14 +182,10 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -212,14 +202,10 @@ public class HttpContentCompressor extends HttpContentEncoder { // This results in the static analysis of native-image identifying the instanceof BrotliOptions check // and thus BrotliOptions itself as unreachable, enabling native-image to link all classes // at build time and not complain about the missing Brotli classes. @@ -73,7 +73,7 @@ } else if (compressionOption instanceof SnappyOptions) { snappyOptions = (SnappyOptions) compressionOption; } else { -@@ -210,8 +196,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -230,8 +216,6 @@ public class HttpContentCompressor extends HttpContentEncoder { this.gzipOptions = gzipOptions; this.deflateOptions = deflateOptions; @@ -82,7 +82,7 @@ this.snappyOptions = snappyOptions; this.factories = new HashMap<String, CompressionEncoderFactory>(); -@@ -222,12 +206,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -242,12 +226,6 @@ public class HttpContentCompressor extends HttpContentEncoder { if (this.deflateOptions != null) { this.factories.put("deflate", new DeflateEncoderFactory()); } @@ -95,7 +95,7 @@ if (this.snappyOptions != null) { this.factories.put("snappy", new SnappyEncoderFactory()); } -@@ -239,13 +217,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -259,13 +237,6 @@ public class HttpContentCompressor extends HttpContentEncoder { options.add(gzipOptions); options.add(deflateOptions); options.add(StandardCompressionOptions.snappy()); @@ -109,7 +109,7 @@ return options.toArray(new CompressionOptions[0]); } -@@ -289,8 +260,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -309,8 +280,6 @@ public class HttpContentCompressor extends HttpContentEncoder { @SuppressWarnings("FloatingPointEquality") protected String determineEncoding(String acceptEncoding) { float starQ = -1.0f; @@ -118,7 +118,7 @@ float snappyQ = -1.0f; float gzipQ = -1.0f; float deflateQ = -1.0f; -@@ -307,10 +276,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -327,10 +296,6 @@ public class HttpContentCompressor extends HttpContentEncoder { } if (encoding.contains("*")) { starQ = q; @@ -129,7 +129,7 @@ } else if (encoding.contains("snappy") && q > snappyQ) { snappyQ = q; } else if (encoding.contains("gzip") && q > gzipQ) { -@@ -319,12 +284,8 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -339,12 +304,8 @@ public class HttpContentCompressor extends HttpContentEncoder { deflateQ = q; } } @@ -144,7 +144,7 @@ return "snappy"; } else if (gzipQ != -1.0f && gzipQ >= deflateQ && this.gzipOptions != null) { return "gzip"; -@@ -333,12 +294,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -353,12 +314,6 @@ public class HttpContentCompressor extends HttpContentEncoder { } } if (starQ > 0.0f) { @@ -157,7 +157,7 @@ if (snappyQ == -1.0f && this.snappyOptions != null) { return "snappy"; } -@@ -423,31 +378,6 @@ public class HttpContentCompressor extends HttpContentEncoder { +@@ -443,31 +398,6 @@ public class HttpContentCompressor extends HttpContentEncoder { } } @@ -190,7 +190,7 @@ * Compression Encoder Factory for create {@link SnappyFrameEncoder} * used to compress http content for snappy content encoding diff --git a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java -index f6fde48862..475a09ae58 100644 +index 21fbad525d..475a09ae58 100644 --- a/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java +++ b/codec-http/src/main/java/io/netty/handler/codec/http/HttpContentDecompressor.java @@ -15,23 +15,17 @@ @@ -223,7 +223,7 @@ } - if (Brotli.isAvailable() && BR.contentEqualsIgnoreCase(contentEncoding)) { - return new EmbeddedChannel(ctx.channel().id(), ctx.channel().metadata().hasDisconnect(), -- ctx.channel().config(), new BrotliDecoder(maxAllocation)); +- ctx.channel().config(), BrotliDecoder.newDecoderWithMaxAllocation(maxAllocation)); - } - if (SNAPPY.contentEqualsIgnoreCase(contentEncoding)) { ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.2PEvmT/_old 2026-09-24 23:02:07.747944090 +0200 +++ /var/tmp/diff_new_pack.2PEvmT/_new 2026-09-24 23:02:07.751944257 +0200 @@ -1,6 +1,6 @@ -mtime: 1785155627 -commit: 38277e1b198c1f2781864029f18a3b495cba772ffbeca0382c88d84dc9505cfe +mtime: 1790249469 +commit: 62d22f494960cc68de93b401c8a0a25f74077f1ca35740b4af7c883755e49ca5 url: https://src.opensuse.org/java-packages/netty -revision: 38277e1b198c1f2781864029f18a3b495cba772ffbeca0382c88d84dc9505cfe +revision: 62d22f494960cc68de93b401c8a0a25f74077f1ca35740b4af7c883755e49ca5 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-24 13:31:09.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ netty-4.1.136.Final.tar.gz -> netty-4.1.138.Final.tar.gz ++++++ ++++ 15527 lines of diff (skipped)
