Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package mupdf for openSUSE:Factory checked 
in at 2026-09-28 10:46:55
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/mupdf (Old)
 and      /work/SRC/openSUSE:Factory/.mupdf.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "mupdf"

Mon Sep 28 10:46:55 2026 rev:81 rq:1380865 version:1.28.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/mupdf/mupdf.changes      2026-09-17 
15:20:49.921534912 +0200
+++ /work/SRC/openSUSE:Factory/.mupdf.new.383539/mupdf.changes  2026-09-28 
10:47:30.897623006 +0200
@@ -1,0 +2,51 @@
+Sun Sep 27 05:56:04 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to 1.28.5:
+  * The PRNG now uses ChaCha20 instead of a 48-bit LCG, and the
+    ChaCha20 stream cipher is new public API (fz_chacha20_init(),
+    fz_chacha20_encrypt())
+  * The regular expression engine moved out of the bundled MuJS into
+    the library itself and is new public API (fz_regcomp(),
+    fz_regexec(), fz_regfree(), new include/mupdf/fitz/regexp.h), so
+    the structured text search behind mutool grep no longer reaches
+    into MuJS internals and can now detect runaway backtracking via
+    REG_RUNAWAY. MuJS was updated to 1.3.10
+  * New public helpers: fz_pool_asprintf(), fz_strcasecmp_ascii(),
+    fz_isalpha(), fz_unconst() and
+    fz_release_stext_block_run_resources()
+  * The x11 and gl viewers accept -f to start fullscreen, the default
+    SVG font size is 16, glyph names of the form gXXXX are read as
+    DOS CP-437, CRLF counts as a single line break when generating PDF
+    text appearances, and structured text now tracks clip_text_bbox
+    separately from text_bbox
+  * Font handling: fix an out-of-bounds write in the CFF subsetter
+    and its stack macros, out-of-bounds reads and table overruns in
+    the TTF subsetter, a memory overwrite in CFF2 subsetting and in
+    cached glyph painting, and an out-of-bounds write in ttc-to-ttf
+    conversion (ghostscript bugs 709720, 709728, 709729, 709735,
+    709737, 709567, 709562, 709588)
+  * Fix a potential heap overwrite in progressive loading, an
+    out-of-bounds write in mutool audit, an out-of-bounds read and a
+    stack overflow in the pdf recolor code, an out-of-bounds write in
+    JPEG loading, an integer overflow in the BMP stride check and an
+    overflow in convert_to_utf8 (ghostscript bugs 709677, 709753,
+    709743, 709742, 709561, 709566)
+  * Add compression-bomb detection for the PNG iCCP chunk and for GIF
+    images; fix an infinite loop in mutool clean on a malicious file
+    and a stack overflow on malformed XPS input (ghostscript bugs
+    709653, 709548, 709480)
+  * fz_available() tolerates a NULL stream, overflowing fz_irect
+    coordinates report INT_MAX extent instead of 0, and numerous
+    leak-on-exception paths across structured text, SVG, outline and
+    name-tree code are fixed
+  * Many more fixes and improvements; see upstream's commit log for
+    the full list
+- Rebase mupdf-system-cmark-gfm.patch: upstream 1.28.5 wires up
+  USE_SYSTEM_CMARK_GFM itself and fixes the SYS_CMARK_CFM_LIBS typo
+  in Makethird, so the patch now only adds -lcmark-gfm-extensions and
+  declares cmark_release_plugins() in place of the private registry.h
+- Rename the shared library subpackage from libmupdf28_4 to
+  libmupdf28_5, following the SONAME libmupdf.so.28.5 which upstream
+  derives from the release version
+
+-------------------------------------------------------------------

Old:
----
  mupdf-1.28.4-source.tar.gz

New:
----
  mupdf-1.28.5-source.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ mupdf.spec ++++++
--- /var/tmp/diff_new_pack.QoYmnB/_old  2026-09-28 10:47:32.903707053 +0200
+++ /var/tmp/diff_new_pack.QoYmnB/_new  2026-09-28 10:47:32.904707095 +0200
@@ -19,10 +19,10 @@
 
 # mupdf sets the shared-library SONAME to libmupdf.so.<minor>.<patch>, so it
 # changes on every upstream release; keep %%sover in sync with the version.
-%define sover 28_4
-%define soversion 28.4
+%define sover 28_5
+%define soversion 28.5
 Name:           mupdf
-Version:        1.28.4
+Version:        1.28.5
 Release:        0
 Summary:        PDF and XPS Viewer and Parser and Rendering Library
 License:        AGPL-3.0-or-later
@@ -31,8 +31,12 @@
 Source1:        %{name}.desktop
 Source2:        %{name}-gl.desktop
 Patch0:         mupdf-no-strip.patch
-# Build against the system cmark-gfm instead of the vendored thirdparty copy
-# (wires up the upstream USE_SYSTEM_CMARK_GFM path, which is incomplete in 
1.28)
+# Build against the system cmark-gfm instead of the vendored thirdparty copy.
+# Upstream 1.28.5 wires up USE_SYSTEM_CMARK_GFM itself (and fixed the
+# SYS_CMARK_CFM_LIBS typo in Makethird), so all that is left is linking
+# cmark-gfm-extensions and declaring the one symbol from the private
+# registry.h that the system library does not install.
+# PATCH-FIX-OPENSUSE mupdf-system-cmark-gfm.patch [email protected] -- link 
cmark-gfm-extensions, declare cmark_release_plugins
 Patch1:         mupdf-system-cmark-gfm.patch
 BuildRequires:  desktop-file-utils
 BuildRequires:  fdupes

++++++ mupdf-1.28.4-source.tar.gz -> mupdf-1.28.5-source.tar.gz ++++++
/work/SRC/openSUSE:Factory/mupdf/mupdf-1.28.4-source.tar.gz 
/work/SRC/openSUSE:Factory/.mupdf.new.383539/mupdf-1.28.5-source.tar.gz differ: 
char 5, line 1

++++++ mupdf-system-cmark-gfm.patch ++++++
--- /var/tmp/diff_new_pack.QoYmnB/_old  2026-09-28 10:47:32.954709190 +0200
+++ /var/tmp/diff_new_pack.QoYmnB/_new  2026-09-28 10:47:32.956709273 +0200
@@ -1,29 +1,16 @@
---- a/Makerules        2026-06-28 07:09:41.855848150 +0200
-+++ b/Makerules        2026-06-28 07:09:56.797528424 +0200
-@@ -283,6 +283,10 @@
-     SYS_BROTLI_CFLAGS := $(shell pkg-config --cflags libbrotlidec 
libbrotlienc)
-     SYS_BROTLI_LIBS := $(shell pkg-config --libs libbrotlidec libbrotlienc)
+--- a/Makerules        2026-09-27 07:38:22.860040457 +0200
++++ b/Makerules        2026-09-27 07:38:23.160074133 +0200
+@@ -286,7 +286,7 @@
    endif
-+  ifeq ($(shell pkg-config --exists libcmark-gfm && echo yes),yes)
-+    SYS_CMARK_GFM_CFLAGS := $(shell pkg-config --cflags libcmark-gfm)
+   ifeq ($(shell pkg-config --exists libcmark-gfm && echo yes),yes)
+     SYS_CMARK_GFM_CFLAGS := $(shell pkg-config --cflags libcmark-gfm)
+-    SYS_CMARK_GFM_LIBS := $(shell pkg-config --libs libcmark-gfm)
 +    SYS_CMARK_GFM_LIBS := $(shell pkg-config --libs libcmark-gfm) 
-lcmark-gfm-extensions
-+  endif
+   endif
  
    HAVE_SYS_LEPTONICA := $(shell pkg-config --exists 'lept >= 1.7.4' && echo 
yes)
-   ifeq ($(HAVE_SYS_LEPTONICA),yes)
---- a/Makethird        2026-06-28 07:09:41.855848150 +0200
-+++ b/Makethird        2026-06-28 07:09:51.084886006 +0200
-@@ -112,7 +112,7 @@
- ifeq ($(USE_CMARK_GFM),yes)
- ifeq ($(USE_SYSTEM_CMARK_GFM),yes)
-   THIRD_CFLAGS += $(SYS_CMARK_GFM_CFLAGS)
--  THIRD_LIBS += $(SYS_CMARK_CFM_LIBS)
-+  THIRD_LIBS += $(SYS_CMARK_GFM_LIBS)
- else
-   THIRD_CFLAGS += $(CMARKGFM_CFLAGS)
-   THIRD_LIBS += $(CMARKCGM_LIBS)
---- a/source/html/md.c 2026-06-28 07:09:41.859848600 +0200
-+++ b/source/html/md.c 2026-06-28 07:10:11.271156064 +0200
+--- a/source/html/md.c 2026-09-27 07:38:22.936048988 +0200
++++ b/source/html/md.c 2026-09-27 07:38:25.640352522 +0200
 @@ -27,7 +27,9 @@
  
  #include "cmark-gfm.h"

Reply via email to