Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package fontconfig for openSUSE:Factory 
checked in at 2026-10-01 16:41:28
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/fontconfig (Old)
 and      /work/SRC/openSUSE:Factory/.fontconfig.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "fontconfig"

Thu Oct  1 16:41:28 2026 rev:104 rq:1379620 version:2.18.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/fontconfig/fontconfig.changes    2026-06-09 
14:12:54.046187273 +0200
+++ /work/SRC/openSUSE:Factory/.fontconfig.new.1253/fontconfig.changes  
2026-10-01 16:41:37.512409476 +0200
@@ -1,0 +2,76 @@
+Sat Sep 19 19:52:26 UTC 2026 - Dirk Müller <[email protected]>
+
+- add 583.patch to protect against a potential type confusion
+
+-------------------------------------------------------------------
+Fri Aug 28 10:22:46 UTC 2026 - Petr Gajdos <[email protected]>
+
+- Update to 2.18.3
+  * ci: Add --werror option to the build script
+  * fc-cat: exit with non-zero if not successfully done
+  * Workaround a longstanding use-after-free warning
+  * Fix a null pointer dereference
+  * Add Noto Sans as system-ui for fallback
+  * Drop Noto Sans CJK KR from 60-nonlatin.conf
+  * Correct sat.orth
+  * Add an orth file for Balinese
+  * Update orth files for jv, so, su, tl to use native scripts
+  * Add orth files for scripts used by Noto font families
+  * Update mni.orth to use Meetei Mayek script
+  * Add orth files for Cuneiform languages (akk, sux, hit)
+  * ci: Suppress abidiff false positives for all internal structs
+  * test: Add cache format compatibility tests for orth file additions
+  * Add orth files for ancient scripts (xna, hlu, ecy)
+  * fc-cache: Create backward-compatible cache symlinks for cross-version 
discovery
+  * ci: Update dependencies
+  * Add implicit rule to update genericfamily property against syntactic-sugar
+  * fc-genconf: Use alias syntactic-sugar instead of the pair of test-edit 
config
+  * Allow to limit the targeted family for TTC
+  * test: Fix test_genconf.py to avoid unexpected family name in testing conf
+  * ci: Enable -Werror in CI
+  * ci: drop duplicate pipelines
+  * ci: cleanup
+  * ci: gate distro jobs until all tests passed
+  * ci: reduce more duplicate jobs
+  * ci: Update base ci-templates
+  * test: Fix compiler warnings
+  * fc-fontations: Allow unnecessary_transmutes lint in bindgen-generated Rust 
code
+  * Fix another compiler warnings
+  * ci: Bump FreeBSD version to 14.4
+  * Fix the compiler warnings on MinGW
+  * Update INSTALL
+  * Fix "FileType is deprecated"
+  * Fix unknown type name locale_t on macOS
+- Update to 2.18.2
+  * test: fix unexpected error when something went wrong in pytest
+  * test: Fix a regression for sysroot in test framework
+  * test: Fix a test case failure when BUILDDIR is under /tmp
+  * test: cleanup
+  * Add .gitignore
+  * meson: Add tests-external-fonts option to disable network-dependent tests
+  * Add .editorconfig
+  * test: improve marker handling
+  * test: Fix a fail on subproject build
+  * test: Do not assume all-files-installed before testing
+  * ci: set SOURCE_DATE_EPOCH to the build script
+  * test: unset SOURCE_DATE_EPOCH for some test cases
+  * Use genericfamily for the search of monospace against :spacing=100
+  * conf.d: Add OpenMoji Color and OpenMoji Black
+  * test: Fix a KeyError
+  * Add a hash table for fonts to generate expected genericfamily
+  * Add Nerd Fonts to the table
+  * doc: Fallback to wkhtmltopdf if no docbook2pdf available
+  * fc-genericfamily: Add Noto fonts
+  * fc-cache: do not generate cache when target directory is in deny list
+  * conf.d/Makefile.am: install 05-macos.conf for macOS only
+  * Add more conditional code for FcLocaleSetCurrent()
+  * Do not ship unnecessary files in archive
+  * fc-genericfamily: Add major missing fonts across multiple categories
+  * Use Special FC_CACHE_VERSION for snapshot
+  * new-version.sh: fix an error
+  * Fix FcNameUnparse regression.
+  * Fix FcNameUnparse regression.
+- modified patches
+  * fontconfig-autoconf269.patch (refreshed)
+
+-------------------------------------------------------------------

Old:
----
  fontconfig-2.18.1.tar.bz2

New:
----
  583.patch
  fontconfig-2.18.3.tar.bz2

----------(New B)----------
  New:
- add 583.patch to protect against a potential type confusion
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ fontconfig.spec ++++++
--- /var/tmp/diff_new_pack.lz8wAD/_old  2026-10-01 16:41:39.460491133 +0200
+++ /var/tmp/diff_new_pack.lz8wAD/_new  2026-10-01 16:41:39.461491175 +0200
@@ -18,7 +18,7 @@
 
 Name:           fontconfig
 %define lname   libfontconfig1
-Version:        2.18.1
+Version:        2.18.3
 Release:        0
 Summary:        Library for Font Configuration
 License:        MIT
@@ -29,6 +29,7 @@
 Source5:        local.conf
 Patch1:         skip-network-test.patch
 Patch2:         fontconfig-autoconf269.patch
+Patch3:         583.patch
 BuildRequires:  automake >= 1.11
 BuildRequires:  gperf
 BuildRequires:  libtool

++++++ 583.patch ++++++
>From 3611892e048e2188955d753bee131b3c470b8d77 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Dominik=20R=C3=B6ttsches?= <[email protected]>
Date: Thu, 17 Sep 2026 16:38:01 +0300
Subject: [PATCH 2/2] Validate cache value types against their object

FcCacheOffsetsValid() decided how to validate the FcValue union payload
of a value in a cache file solely from FcValue.type, the FcObject of the
owning FcPatternElt was only used as an address bound and never read.

Users of a pattern however pick the accessor for a value by its object,
not by the type stored alongside it: FcObjectValidType() guarantees that
both agree, but it is only enforced when values are added at runtime,
not for the mmapped patterns FcConfigAddCache() adds to the font set.

A crafted cache could therefore store e.g. FC_FAMILY, registered as
FcTypeString, as an FcTypeInteger: the integer arm of the switch
statement accepted the 64 bit union payload verbatim, bypassing the
FcIsEncodedOffset() check of the string arm, while FcCompareFamilies()
later dereferenced that payload through FcValueString().

Reject values whose type doesn't match the type registered for their
object. Values of objects unknown to this version of fontconfig keep
being accepted, their registered type is FcTypeUnknown.

Fixes #563.

Changelog: fixed
---
 src/fccache.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/src/fccache.c b/src/fccache.c
index cdb36eab..e9ea3cc3 100644
--- a/src/fccache.c
+++ b/src/fccache.c
@@ -940,6 +940,21 @@ FcCacheOffsetsValid (FcCache *cache)
                    if ((char *)l < last_offset || (char *)l > end - sizeof 
(*l) ||
                        (l->next != NULL && !FcIsEncodedOffset (l->next)))
                        return FcFalse;
+                   /* The checks below are driven by the type stored in the
+                    * value, whereas the users of a pattern pick the accessor
+                    * for a value by the object it belongs to. Reject values
+                    * whose type doesn't match the type registered for the
+                    * object, otherwise e.g. an integer stored for FC_FAMILY
+                    * would be accepted here without validating the union,
+                    * but dereferenced as a string later on.
+                    */
+                   if (!FcObjectValidType (e[j].object, l->value.type)) {
+                       if (FcDebug() & FC_DBG_CACHE) {
+                           fprintf (stderr, "Fontconfig warning: invalid 
cache: value of type %d doesn't match the type of object %d\n",
+                                    l->value.type, e[j].object);
+                       }
+                       return FcFalse;
+                   }
                    switch (l->value.type) {
                    case FcTypeVoid:
                    case FcTypeInteger:
-- 

++++++ fontconfig-2.18.1.tar.bz2 -> fontconfig-2.18.3.tar.bz2 ++++++
++++ 12151 lines of diff (skipped)

++++++ fontconfig-autoconf269.patch ++++++
--- /var/tmp/diff_new_pack.lz8wAD/_old  2026-10-01 16:41:40.733544495 +0200
+++ /var/tmp/diff_new_pack.lz8wAD/_new  2026-10-01 16:41:40.748545124 +0200
@@ -1,7 +1,7 @@
-Index: fontconfig-2.18.0/configure.ac
+Index: fontconfig-2.18.3/configure.ac
 ===================================================================
---- fontconfig-2.18.0.orig/configure.ac
-+++ fontconfig-2.18.0/configure.ac
+--- fontconfig-2.18.3.orig/configure.ac
++++ fontconfig-2.18.3/configure.ac
 @@ -23,7 +23,7 @@ dnl  PERFORMANCE OF THIS SOFTWARE.
  dnl
  dnl Process this file with autoconf to create configure.
@@ -11,7 +11,7 @@
  
  dnl ==========================================================================
  dnl                               Versioning
-@@ -182,7 +182,7 @@ dnl ====================================
+@@ -192,7 +192,7 @@ dnl ====================================
  AC_HEADER_DIRENT
  # Autoupdate added the next two lines to ensure that your configure
  # script's behavior did not change.  They are probably safe to remove.

Reply via email to