Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package otpclient for openSUSE:Factory 
checked in at 2026-09-28 10:45:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/otpclient (Old)
 and      /work/SRC/openSUSE:Factory/.otpclient.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "otpclient"

Mon Sep 28 10:45:34 2026 rev:57 rq:1380792 version:5.2.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/otpclient/otpclient.changes      2026-09-22 
15:55:03.367786690 +0200
+++ /work/SRC/openSUSE:Factory/.otpclient.new.383539/otpclient.changes  
2026-09-28 10:46:06.466085641 +0200
@@ -1,0 +2,115 @@
+Sat Sep 26 11:59:08 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update to version 5.2.2:
+  + Flatpak:
+    - FIX: inside the Flatpak, the search provider's "code copied"
+      and failure notifications go through
+      org.freedesktop.portal.Notification instead of
+      org.freedesktop.Notifications, so the sandbox no longer needs
+      that permission. The code notification is marked transient
+      only once the portal reports version 2 or later, and is
+      withdrawn after five seconds regardless, so it does not
+      linger in history on version 1 backends such as KDE's
+  + Documentation:
+    - The README now describes minimize-to-tray as the runtime
+      setting it has been since 5.1.7, lists the full CLI surface,
+      and documents the SANITIZE build option, PIE and the
+      RELRO/BIND_NOW link flags
+    - The settings dialog no longer tells users a keyword change
+      needs a logout; the provider has reloaded it immediately for
+      a while now. Translation templates regenerated
+
+-------------------------------------------------------------------
+Wed Sep 23 07:58:05 UTC 2026 - Paolo Stivanin <[email protected]>
+
+- Update to 5.2.1:
+  * FIX: replacing the active database while an unlock was still
+    running could free the state the worker was reading. Opening or
+    creating another database is now refused until the unlock
+    finishes, keyring replies for a database that is no longer
+    active are discarded, and a second concurrent unlock worker is
+    refused
+  * FIX: a token could be silently lost to an out-of-memory
+    condition during a save, because merging the quarantined tokens
+    into the database ignored a failed append and the atomic replace
+    made the omission permanent. The append is now checked and the
+    save aborts before anything reaches disk; the same rule applies
+    to imports and to the extraction of invalid tokens
+  * FIX: the external-modification guard could be armed with a stale
+    hash and then refuse every save with "Database changed on disk".
+    The baseline is now derived from the exact bytes the commit
+    wrote, and where hashing is unavailable the guard is disabled
+    for that generation with a journal warning
+  * FIX: moving a token to another database could delete it if
+    staging the token in the target failed; the move now verifies
+    the source database and its generation, and the token's own
+    contents, before removing anything
+  * FIX: the importers and exporters stopped trusting sizes and
+    lengths they could not verify. Aegis, Authenticator Pro, 2FAS
+    and FreeOTP imports reject a failed file-size probe,
+    Authenticator Pro verifies the backup's header, period-less
+    2FAS tokens get the 30-second default, the second JSON dump must
+    return the exact length before a database is replaced or an
+    export is called successful, and Base32 validation rejects a
+    secret made only of padding
+  * SECURITY: a crafted Aegis backup could force a 1 GiB allocation
+    and a long scrypt run before authentication had a chance to
+    reject it. The scrypt parameters are now bounded (n up to 2^17,
+    and n times p up to 2^20)
+  * SECURITY: the search provider's rate limit was a single global
+    bucket, so a local peer that knew the trigger keyword could keep
+    it drained and starve the real user. The buckets are now keyed
+    on the D-Bus sender, with a bounded map and least-recently-seen
+    eviction
+  * FIX: a wedged Secret Service held the search provider's entry
+    reload open forever. Every keyring lookup now carries a
+    cancellable 30-second deadline
+  * FIX: activating a search result resolved it by position, so an
+    entry list that changed in between could copy another account's
+    code. Results are now resolved by a stable token identity
+    (issuer, label and contents), and an ambiguous match is refused
+  * FIX: a rejected password showed no reason why, because the
+    unlock dialog cleared its fields before displaying the error.
+    The error is now set after the fields are cleared, and a retry
+    after a failed unlock arrives with the reason the last attempt
+    failed
+  * FIX: a delayed TOTP refresh tick could hide a freshly generated
+    code or leave an expired one on screen. Generation and the
+    recorded step now share one sampled timestamp, and
+    cross-database search results are included in that bookkeeping
+  * FIX: the validity countdown's colors bled across rows. The two
+    configured colors now live in one shared CSS provider and each
+    row carries a class
+  * FIX: locking and unlocking the database filtered every grouped
+    token out of the list, because an invalid group selection
+    recorded the empty-string "Ungrouped" sentinel as the user's
+    choice. An invalid selection now means "All"
+  * FIX: a drag-reorder that failed to commit could leave the
+    on-screen row bound to another entry; the list is now rebuilt
+    from the database when a reorder fails. A fatal unlock failure
+    now refreshes the content page instead of leaving it stale, and
+    import and file-chooser callbacks are bound to the database and
+    session they were started from
+  * FIX: a discarded QR result is now wiped, per-row CSS providers
+    and combo row string lists are released, the clipboard timer is
+    cleared, an export to a non-native path is rejected, and
+    parse-uri wipes its split-line copies of the secret
+  * FIX: with minimize-to-tray enabled, unlocking the desktop
+    brought the window back and gave it focus even though it had
+    been left in the tray. Tray recovery is now suspended for as
+    long as the desktop is locked and resumes at unlock with a
+    fresh grace period only if the icon still has not returned; the
+    desktop's lock state is now tracked for this regardless of
+    whether Auto-Lock is enabled (#473)
+  * FIX: the command line's password prompt treated a read error as
+    the end of input, passing a partial password on to surface later
+    as a baffling "Incorrect password"; a failed read now names the
+    error and stops. A keyring password that cannot be copied into
+    secure memory no longer records itself as stored while holding
+    nothing, and fails with the memlock message instead. The
+    database-list JSON output no longer prints "(null)" and exits
+    successfully when serialization fails, and a settings export
+    whose second JSON dump fails is no longer returned as an empty
+    success
+
+-------------------------------------------------------------------

Old:
----
  v5.2.0.tar.gz
  v5.2.0.tar.gz.asc

New:
----
  v5.2.2.tar.gz
  v5.2.2.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ otpclient.spec ++++++
--- /var/tmp/diff_new_pack.NMaS7I/_old  2026-09-28 10:46:07.835143000 +0200
+++ /var/tmp/diff_new_pack.NMaS7I/_new  2026-09-28 10:46:07.839143167 +0200
@@ -18,7 +18,7 @@
 
 %define uclname OTPClient
 Name:           otpclient
-Version:        5.2.0
+Version:        5.2.2
 Release:        0
 Summary:        Simple GTK+ client for managing TOTP and HOTP
 License:        GPL-3.0-or-later

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.NMaS7I/_old  2026-09-28 10:46:07.910146142 +0200
+++ /var/tmp/diff_new_pack.NMaS7I/_new  2026-09-28 10:46:07.923146687 +0200
@@ -1,7 +1,7 @@
-mtime: 1789587211
-commit: 05e32087e9bc19d18ec6fbc6d3d9001d6a4d3f68a220ce56770d8d659f5da235
+mtime: 1790425958
+commit: 2febcb101e99f9722a81a2f5f62e8423a43c688315d9dbeec7217cbc2b16b6fa
 url: https://src.opensuse.org/GNOME/otpclient
-revision: 05e32087e9bc19d18ec6fbc6d3d9001d6a4d3f68a220ce56770d8d659f5da235
+revision: 2febcb101e99f9722a81a2f5f62e8423a43c688315d9dbeec7217cbc2b16b6fa
 trackingbranch: factory
 projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj
 

++++++ build.specials.obscpio ++++++
--- old/.gitignore      2026-09-16 21:33:31.000000000 +0200
+++ new/.gitignore      2026-09-26 14:32:38.000000000 +0200
@@ -2,3 +2,4 @@
 *.osc
 _build.*
 .pbuild
+osc-collab.*

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-26 14:32:38.000000000 +0200
@@ -0,0 +1,5 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild
+osc-collab.*


++++++ v5.2.0.tar.gz -> v5.2.2.tar.gz ++++++
++++ 5942 lines of diff (skipped)

Reply via email to