Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package systemd for openSUSE:Factory checked in at 2026-10-01 16:41:19 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/systemd (Old) and /work/SRC/openSUSE:Factory/.systemd.new.1253 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "systemd" Thu Oct 1 16:41:19 2026 rev:474 rq:1381350 version:261.3 Changes: -------- --- /work/SRC/openSUSE:Factory/systemd/systemd.changes 2026-07-28 17:50:28.540875917 +0200 +++ /work/SRC/openSUSE:Factory/.systemd.new.1253/systemd.changes 2026-10-01 16:41:31.071139480 +0200 @@ -1,0 +2,28 @@ +Tue Sep 22 13:32:00 UTC 2026 - Franck Bui <[email protected]> + +- pam: use "pam_rootok" in the "auth" stack of our PAM config for systemd-run0 + (bsc#1253133) and similarly update our PAM config for systemd-user to replace + "pam_deny" with "pam_rootok". + + Previously SUSE PAM config used for systemd user instances already relied on + "pam_deny" for the PAM "auth" management to avoid falling back on the noisy + "other" pam service (see bsc#1190515). However "pam_deny" had the drawback to + still log the failure at the debug level. SUSE PAM configs now consistently + rely on "pam_rootok" to avoid any noisy debug logs, see upstream commit + 34e5f14c3496097c4157a5ed8a13ed4c4b1c48a9. + +------------------------------------------------------------------- +Mon Sep 21 13:34:25 UTC 2026 - Franck Bui <[email protected]> + +- Import commit 3255daee1572366b74fe92f002a3d60ecbb27103 (merge of v261.3) + + For a complete list of changes, visit: + https://github.com/openSUSE/systemd/compare/4925d9f07fc697efccd98a93046ff535b8832445...3255daee1572366b74fe92f002a3d60ecbb27103 + +------------------------------------------------------------------- +Fri Aug 14 08:15:21 UTC 2026 - Alberto Planas Dominguez <[email protected]> + +- Move systemd-pcrextend from experimental to udev (bsc#1274948) +- Move systemd-measure from experimental to udev to fix ukify + +------------------------------------------------------------------- Old: ---- systemd-261.2.tar.xz New: ---- systemd-261.3.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ systemd.spec ++++++ --- /var/tmp/diff_new_pack.SAkprw/_old 2026-10-01 16:41:32.959218621 +0200 +++ /var/tmp/diff_new_pack.SAkprw/_new 2026-10-01 16:41:32.962218747 +0200 @@ -31,7 +31,7 @@ %bcond_with obs_service_set_version %if %{without obs_service_set_version} -%define systemd_version 261.2 +%define systemd_version 261.3 %define systemd_release 0 %define archive_version %{nil} %endif @@ -656,9 +656,8 @@ Components that turn out to be stable and considered as fully supported will be merged into the main package or moved into a dedicated package. -Currently this package contains the following features : bsod, oomd, measure, -pcrextend, pcrlock, ssh-generator, storagetm, sysupdate. -tpm2-setup and userwork. +Currently this package contains the following features : bsod, oomd, +ssh-generator, storagetm, sysupdate, tpm2-setup and userwork. Have fun (at your own risk). ++++++ files.experimental ++++++ --- /var/tmp/diff_new_pack.SAkprw/_old 2026-10-01 16:41:33.101224574 +0200 +++ /var/tmp/diff_new_pack.SAkprw/_new 2026-10-01 16:41:33.104224700 +0200 @@ -23,7 +23,6 @@ %dir %{_unitdir}/factory-reset.target.wants %if %{with sd_boot} %dir %{_unitdir}/initrd.target.wants -%dir %{_unitdir}/storage-target-mode.target.wants %endif %if %{without bootstrap} %dir %{_unitdir}/system-install.target.wants @@ -38,13 +37,16 @@ %{_bindir}/systemd-mute-console %if %{without bootstrap} %{_bindir}/systemd-sysinstall +%if %{without upstream} %{_bindir}/systemd-sysupdate +%endif %{_bindir}/updatectl %{_datadir}/bash-completion/completions/oomctl %{_datadir}/bash-completion/completions/storagectl %{_datadir}/bash-completion/completions/systemd-sysinstall %if %{with upstream} %{_datadir}/bash-completion/completions/systemd-sysupdate +%{_datadir}/bash-completion/completions/updatectl %endif %{_datadir}/dbus-1/interfaces/org.freedesktop.oom1.Manager.xml %{_datadir}/dbus-1/interfaces/org.freedesktop.sysupdate1.Job.xml @@ -67,6 +69,7 @@ %{_datadir}/zsh/site-functions/_systemd-sysinstall %if %{with upstream} %{_datadir}/zsh/site-functions/_systemd-sysupdate +%{_datadir}/zsh/site-functions/_updatectl %endif %endif %{_distconfdir}/ssh/ssh_config.d/20-systemd-ssh-proxy.conf @@ -78,7 +81,6 @@ %{_mandir}/man1/systemd-imds-import.service.1.gz %{_mandir}/man1/systemd-imds.1.gz %{_mandir}/man1/systemd-keyutil.1.gz -%{_mandir}/man1/systemd-measure.1.gz %{_mandir}/man1/systemd-mstack.1.gz %{_mandir}/man1/systemd-mute-console.1.gz %{_mandir}/man1/systemd-mute-console.socket.1.gz @@ -107,6 +109,8 @@ %{_mandir}/man8/systemd-clonesetup-generator.8.gz %{_mandir}/man8/systemd-clonesetup.8.gz %{_mandir}/man8/[email protected] +%{_mandir}/man8/systemd-coredump-register.service.8.gz +%{_mandir}/man8/systemd-coredumpd.service.8.gz %endif %{_mandir}/man8/systemd-factory-reset-complete.service.8.gz %{_mandir}/man8/systemd-factory-reset-generator.8.gz @@ -125,9 +129,6 @@ %{_mandir}/man8/systemd-oomd.8.gz %{_mandir}/man8/systemd-oomd.service.8.gz %if %{with sd_boot} -%{_mandir}/man8/systemd-pcrextend.8.gz -%{_mandir}/man8/systemd-pcrfs-root.service.8.gz -%{_mandir}/man8/[email protected] %{_mandir}/man8/systemd-pcrlock-file-system.service.8.gz %{_mandir}/man8/systemd-pcrlock-firmware-code.service.8.gz %{_mandir}/man8/systemd-pcrlock-firmware-config.service.8.gz @@ -135,16 +136,6 @@ %{_mandir}/man8/systemd-pcrlock-make-policy.service.8.gz %{_mandir}/man8/systemd-pcrlock-secureboot-authority.service.8.gz %{_mandir}/man8/systemd-pcrlock-secureboot-policy.service.8.gz -%{_mandir}/man8/[email protected] -%{_mandir}/man8/systemd-pcrmachine.service.8.gz -%{_mandir}/man8/systemd-pcrnvdone.service.8.gz -%{_mandir}/man8/systemd-pcrosseparator.service.8.gz -%{_mandir}/man8/systemd-pcrphase-factory-reset.service.8.gz -%{_mandir}/man8/systemd-pcrphase-initrd.service.8.gz -%{_mandir}/man8/systemd-pcrphase-storage-target-mode.service.8.gz -%{_mandir}/man8/systemd-pcrphase-sysinit.service.8.gz -%{_mandir}/man8/systemd-pcrphase.service.8.gz -%{_mandir}/man8/systemd-pcrproduct.service.8.gz %endif %if %{with upstream} %{_mandir}/man8/systemd-report-files.8.gz @@ -153,6 +144,9 @@ %{_mandir}/man8/systemd-report-sign-plain.8.gz %{_mandir}/man8/systemd-report-sign-plain.socket.8.gz %{_mandir}/man8/[email protected] +%{_mandir}/man8/systemd-report-sign-tpm2.8.gz +%{_mandir}/man8/systemd-report-sign-tpm2.socket.8.gz +%{_mandir}/man8/[email protected] %{_mandir}/man8/systemd-report-sign-tsm.8.gz %{_mandir}/man8/systemd-report-sign-tsm.socket.8.gz %{_mandir}/man8/[email protected] @@ -224,18 +218,15 @@ %{_systemd_util_dir}/systemd-imds %{_systemd_util_dir}/systemd-imdsd %{_systemd_util_dir}/systemd-keyutil -%{_systemd_util_dir}/systemd-measure %{_systemd_util_dir}/systemd-oomd %endif -%if %{with sd_boot} -%{_systemd_util_dir}/systemd-pcrextend -%endif %{_systemd_util_dir}/systemd-report %{_systemd_util_dir}/systemd-report-basic %{_systemd_util_dir}/systemd-report-cgroup %if %{with upstream} %{_systemd_util_dir}/systemd-report-files %{_systemd_util_dir}/systemd-report-sign-plain +%{_systemd_util_dir}/systemd-report-sign-tpm2 %{_systemd_util_dir}/systemd-report-sign-tsm %endif %if %{without bootstrap} @@ -279,21 +270,12 @@ %endif %{_unitdir}/factory-reset-now.target %{_unitdir}/factory-reset.target.wants/systemd-factory-reset-request.service -%if %{with sd_boot} -%{_unitdir}/factory-reset.target.wants/systemd-pcrphase-factory-reset.service -%endif %if %{without bootstrap} %{_unitdir}/initrd.target.wants/systemd-bsod.service %endif -%if %{with sd_boot} -%{_unitdir}/initrd.target.wants/systemd-pcrphase-initrd.service -%endif %{_unitdir}/sockets.target.wants/systemd-factory-reset.socket %{_unitdir}/sockets.target.wants/systemd-journalctl.socket %{_unitdir}/sockets.target.wants/systemd-mute-console.socket -%if %{with sd_boot} -%{_unitdir}/sockets.target.wants/systemd-pcrextend.socket -%endif %{_unitdir}/sockets.target.wants/systemd-storage-block.socket %{_unitdir}/sockets.target.wants/systemd-storage-fs.socket %if %{with upstream} @@ -304,16 +286,9 @@ %{_unitdir}/storage-target-mode.target %endif %if %{with sd_boot} -%{_unitdir}/storage-target-mode.target.wants/systemd-pcrphase-storage-target-mode.service %if %{with upstream} %{_unitdir}/sysinit.target.wants/clonesetup.target %endif -%{_unitdir}/sysinit.target.wants/systemd-pcrmachine.service -%{_unitdir}/sysinit.target.wants/systemd-pcrnvdone.service -%{_unitdir}/sysinit.target.wants/systemd-pcrosseparator.service -%{_unitdir}/sysinit.target.wants/systemd-pcrphase-sysinit.service -%{_unitdir}/sysinit.target.wants/systemd-pcrphase.service -%{_unitdir}/sysinit.target.wants/systemd-pcrproduct.service %{_unitdir}/sysinit.target.wants/systemd-tpm2-setup-early.service %{_unitdir}/sysinit.target.wants/systemd-tpm2-setup.service %endif @@ -325,6 +300,10 @@ %if %{without bootstrap} %{_unitdir}/systemd-bsod.service %endif +%if %{with upstream} +%{_unitdir}/systemd-coredump-register.service +%{_unitdir}/systemd-coredumpd.service +%endif %{_unitdir}/systemd-factory-reset-complete.service %{_unitdir}/systemd-factory-reset-reboot.service %{_unitdir}/systemd-factory-reset-request.service @@ -359,10 +338,6 @@ %{_unitdir}/systemd-oomd.socket %endif %if %{with sd_boot} -%{_unitdir}/systemd-pcrextend.socket -%{_unitdir}/[email protected] -%{_unitdir}/systemd-pcrfs-root.service -%{_unitdir}/[email protected] %{_unitdir}/systemd-pcrlock-file-system.service %{_unitdir}/systemd-pcrlock-firmware-code.service %{_unitdir}/systemd-pcrlock-firmware-config.service @@ -371,16 +346,6 @@ %{_unitdir}/systemd-pcrlock-secureboot-authority.service %{_unitdir}/systemd-pcrlock-secureboot-policy.service %{_unitdir}/[email protected] -%{_unitdir}/[email protected] -%{_unitdir}/systemd-pcrmachine.service -%{_unitdir}/systemd-pcrnvdone.service -%{_unitdir}/systemd-pcrosseparator.service -%{_unitdir}/systemd-pcrphase-factory-reset.service -%{_unitdir}/systemd-pcrphase-initrd.service -%{_unitdir}/systemd-pcrphase-storage-target-mode.service -%{_unitdir}/systemd-pcrphase-sysinit.service -%{_unitdir}/systemd-pcrphase.service -%{_unitdir}/systemd-pcrproduct.service %endif %{_unitdir}/systemd-report-basic.socket %{_unitdir}/[email protected] @@ -391,6 +356,8 @@ %{_unitdir}/[email protected] %{_unitdir}/systemd-report-sign-plain.socket %{_unitdir}/[email protected] +%{_unitdir}/systemd-report-sign-tpm2.socket +%{_unitdir}/[email protected] %{_unitdir}/systemd-report-sign-tsm.socket %{_unitdir}/[email protected] %{_unitdir}/systemd-report.socket ++++++ files.udev ++++++ --- /var/tmp/diff_new_pack.SAkprw/_old 2026-10-01 16:41:33.251230861 +0200 +++ /var/tmp/diff_new_pack.SAkprw/_new 2026-10-01 16:41:33.254230987 +0200 @@ -43,7 +43,13 @@ %dir %{_systemd_util_dir}/system-sleep %dir %{_udevhwdbdir} %dir %{_udevrulesdir} +%if %{with sd_boot} +%dir %{_unitdir}/factory-reset.target.wants +%endif %dir %{_unitdir}/initrd.target.wants +%if %{with sd_boot} +%dir %{_unitdir}/storage-target-mode.target.wants +%endif %if %{without bootstrap} %doc %{_udevhwdbdir}/README %endif @@ -94,6 +100,7 @@ %if %{with docs} %{_mandir}/man1/bootctl.1.gz %{_mandir}/man1/systemd-cryptenroll.1.gz +%{_mandir}/man1/systemd-measure.1.gz %{_mandir}/man5/crypttab.5.gz %{_mandir}/man5/integritytab.5.gz %{_mandir}/man5/iocost.conf.5.gz @@ -156,7 +163,20 @@ %{_mandir}/man8/systemd-network-generator.8.gz %{_mandir}/man8/systemd-network-generator.service.8.gz %if %{with sd_boot} +%{_mandir}/man8/systemd-pcrextend.8.gz +%{_mandir}/man8/systemd-pcrfs-root.service.8.gz +%{_mandir}/man8/[email protected] %{_mandir}/man8/systemd-pcrlock.8.gz +%{_mandir}/man8/[email protected] +%{_mandir}/man8/systemd-pcrmachine.service.8.gz +%{_mandir}/man8/systemd-pcrnvdone.service.8.gz +%{_mandir}/man8/systemd-pcrosseparator.service.8.gz +%{_mandir}/man8/systemd-pcrphase-factory-reset.service.8.gz +%{_mandir}/man8/systemd-pcrphase-initrd.service.8.gz +%{_mandir}/man8/systemd-pcrphase-storage-target-mode.service.8.gz +%{_mandir}/man8/systemd-pcrphase-sysinit.service.8.gz +%{_mandir}/man8/systemd-pcrphase.service.8.gz +%{_mandir}/man8/systemd-pcrproduct.service.8.gz %endif %{_mandir}/man8/systemd-pstore.8.gz %{_mandir}/man8/systemd-pstore.service.8.gz @@ -265,9 +285,13 @@ %endif %{_systemd_util_dir}/systemd-makefs %if %{without bootstrap} +%{_systemd_util_dir}/systemd-measure %{_systemd_util_dir}/systemd-modules-load %endif %{_systemd_util_dir}/systemd-network-generator +%if %{with sd_boot} +%{_systemd_util_dir}/systemd-pcrextend +%endif %if %{without bootstrap} %{_systemd_util_dir}/systemd-pcrlock %endif @@ -364,7 +388,9 @@ %{_udevrulesdir}/60-persistent-v4l.rules %{_udevrulesdir}/60-sensor.rules %{_udevrulesdir}/60-serial.rules +%if %{without bootstrap} %{_udevrulesdir}/60-tpm2-id.rules +%endif %{_udevrulesdir}/64-btrfs.rules %{_udevrulesdir}/65-integration.rules %{_udevrulesdir}/70-camera.rules @@ -392,6 +418,9 @@ %{_unitdir}/cryptsetup-pre.target %{_unitdir}/cryptsetup.target %endif +%if %{with sd_boot} +%{_unitdir}/factory-reset.target.wants/systemd-pcrphase-factory-reset.service +%endif %{_unitdir}/hibernate.target %{_unitdir}/hybrid-sleep.target %if %{without bootstrap} @@ -404,6 +433,9 @@ %if %{with upstream} %{_unitdir}/initrd.target.wants/systemd-cryptenroll-firstboot.service %endif +%if %{with sd_boot} +%{_unitdir}/initrd.target.wants/systemd-pcrphase-initrd.service +%endif %if %{without bootstrap} %{_unitdir}/integritysetup-pre.target %{_unitdir}/integritysetup.target @@ -424,6 +456,7 @@ %{_unitdir}/sockets.target.wants/systemd-cryptenroll.socket %endif %if %{with sd_boot} +%{_unitdir}/sockets.target.wants/systemd-pcrextend.socket %{_unitdir}/sockets.target.wants/systemd-pcrlock.socket %endif %if %{without bootstrap} @@ -434,6 +467,9 @@ %endif %{_unitdir}/sockets.target.wants/systemd-udevd-kernel.socket %{_unitdir}/sockets.target.wants/systemd-udevd-varlink.socket +%if %{with sd_boot} +%{_unitdir}/storage-target-mode.target.wants/systemd-pcrphase-storage-target-mode.service +%endif %{_unitdir}/suspend-then-hibernate.target %{_unitdir}/suspend.target %if %{without bootstrap} @@ -448,6 +484,14 @@ %{_unitdir}/sysinit.target.wants/systemd-hwdb-update.service %{_unitdir}/sysinit.target.wants/systemd-modules-load.service %endif +%if %{with sd_boot} +%{_unitdir}/sysinit.target.wants/systemd-pcrmachine.service +%{_unitdir}/sysinit.target.wants/systemd-pcrnvdone.service +%{_unitdir}/sysinit.target.wants/systemd-pcrosseparator.service +%{_unitdir}/sysinit.target.wants/systemd-pcrphase-sysinit.service +%{_unitdir}/sysinit.target.wants/systemd-pcrphase.service +%{_unitdir}/sysinit.target.wants/systemd-pcrproduct.service +%endif %{_unitdir}/sysinit.target.wants/systemd-random-seed.service %{_unitdir}/sysinit.target.wants/systemd-tmpfiles-setup-dev-early.service %{_unitdir}/sysinit.target.wants/systemd-tmpfiles-setup-dev.service @@ -489,7 +533,21 @@ %endif %{_unitdir}/systemd-network-generator.service %if %{with sd_boot} +%{_unitdir}/systemd-pcrextend.socket +%{_unitdir}/[email protected] +%{_unitdir}/systemd-pcrfs-root.service +%{_unitdir}/[email protected] %{_unitdir}/systemd-pcrlock.socket +%{_unitdir}/[email protected] +%{_unitdir}/systemd-pcrmachine.service +%{_unitdir}/systemd-pcrnvdone.service +%{_unitdir}/systemd-pcrosseparator.service +%{_unitdir}/systemd-pcrphase-factory-reset.service +%{_unitdir}/systemd-pcrphase-initrd.service +%{_unitdir}/systemd-pcrphase-storage-target-mode.service +%{_unitdir}/systemd-pcrphase-sysinit.service +%{_unitdir}/systemd-pcrphase.service +%{_unitdir}/systemd-pcrproduct.service %endif %{_unitdir}/systemd-pstore.service %{_unitdir}/systemd-quotacheck-root.service ++++++ pam.systemd-run0 ++++++ --- /var/tmp/diff_new_pack.SAkprw/_old 2026-10-01 16:41:33.334234341 +0200 +++ /var/tmp/diff_new_pack.SAkprw/_new 2026-10-01 16:41:33.337234466 +0200 @@ -5,6 +5,17 @@ account include common-account +# systemd never invokes pam_authenticate() on this stack (authorization for run0 +# is done via polkit), but it does invoke pam_setcred(), which runs the "auth" +# stack too. Hence an "auth" entry is needed that lets pam_setcred() succeed, +# without falling back to the "other" service (which typically consists of +# pam_warn/pam_deny, and thus generates log noise). pam_rootok's +# pam_sm_setcred() unconditionally succeeds, while its pam_sm_authenticate() +# only succeeds for callers running as root (which the service manager does). +# See bsc#1253133 for details. + +auth required pam_rootok.so + session required pam_selinux.so close session required pam_selinux.so open session required pam_loginuid.so ++++++ pam.systemd-user ++++++ --- /var/tmp/diff_new_pack.SAkprw/_old 2026-10-01 16:41:33.361235472 +0200 +++ /var/tmp/diff_new_pack.SAkprw/_new 2026-10-01 16:41:33.366235682 +0200 @@ -2,19 +2,16 @@ # # Used by systemd --user instances. -# Override the default behavior of the "auth" PAM stack and don't throw a -# warning each time a user instance is started, which is the default behavior of -# the PAM stack when no auth is defined. Indeed PID1 calls pam_setcred() when -# the user instance is about to be started to allow some user services, such as -# gnome-terminal, to extend theirs credentials similar to the ones received by a -# user when he logs in (and the full PAM authentication stack is run). For some -# details, see: -# -# https://gitlab.gnome.org/GNOME/gdm/-/issues/393 -# https://github.com/systemd/systemd/issues/11198 -# https://bugzilla.suse.com/show_bug.cgi?id=1190515 -# -auth required pam_deny.so +# systemd never invokes pam_authenticate() on this stack (authorization for run0 +# is done via polkit), but it does invoke pam_setcred(), which runs the "auth" +# stack too. Hence an "auth" entry is needed that lets pam_setcred() succeed, +# without falling back to the "other" service (which typically consists of +# pam_warn/pam_deny, and thus generates log noise). pam_rootok's +# pam_sm_setcred() unconditionally succeeds, while its pam_sm_authenticate() +# only succeeds for callers running as root (which the service manager does). +# See bsc#1190515 for details. + +auth required pam_rootok.so account required pam_unix.so no_pass_expiry ++++++ systemd-261.2.tar.xz -> systemd-261.3.tar.xz ++++++ /work/SRC/openSUSE:Factory/systemd/systemd-261.2.tar.xz /work/SRC/openSUSE:Factory/.systemd.new.1253/systemd-261.3.tar.xz differ: char 15, line 1
