Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package NetworkManager for openSUSE:Factory 
checked in at 2026-10-02 23:01:21
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/NetworkManager (Old)
 and      /work/SRC/openSUSE:Factory/.NetworkManager.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "NetworkManager"

Fri Oct  2 23:01:21 2026 rev:296 rq:1381857 version:1.58.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/NetworkManager/NetworkManager.changes    
2026-09-07 11:26:29.696018505 +0200
+++ 
/work/SRC/openSUSE:Factory/.NetworkManager.new.1631729/NetworkManager.changes   
    2026-10-02 23:01:40.882119125 +0200
@@ -1,0 +2,192 @@
+Thu Oct  1 09:37:50 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Disable 464XLAT Customer-side Translator (CLAT) support on %ix86:
+  + Introduce bcond_with/withot bpf build condition, based on arch
+  + Pass -Dclat=false to meson when bpf is disabled
+  + Only conditionally BuildRequire libbpf and cross-bpf-gcc
+
+-------------------------------------------------------------------
+Wed Sep 30 15:07:29 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update version dependencies according to meson.build.
+
+-------------------------------------------------------------------
+Thu Sep 24 12:50:31 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update to version 1.58.1:
+  + Overview of changes since NetworkManager-1.58.0:
+    - For private connections (the ones that specify a user in the
+      "connection.permissions" property), the 802.1X "ca-path" and
+      "phase2-ca-path" properties are no longer accepted and
+      activation fails, as the daemon would otherwise let the owner
+      of the profile choose the CA trust store used to validate the
+      authentication server. Such profiles must clear those
+      properties and use "ca-cert" or "system-ca-certs" instead.
+    - Fix IPv4 forwarding not enabled on modem data interfaces.
+    - Log a warning when ignoring DHCPv4 option 3 (Router) due to
+      the presence of option 121/249 (Classless Static Routes)
+      results in no gateway.
+    - Set the parent interface by name for NBFT VLAN connections in
+      the initrd generator to avoid race conditions at boot.
+    - Perform the connectivity check also when the interface only
+      has an IPv4 link-scope default route.
+    - Ignore unspecified addresses as DNS nameservers from RDNSS
+      and DHCPv6, and skip invalid nameservers when configuring
+      systemd-resolved.
+    - Fix auto-connect to SAE (WPA3) networks with key-mgmt=wpa-psk
+      profiles.
+    - Fix DNS server port number not forwarded to systemd-resolved
+      for DNS URIs.
+    - Fix normalization of Bluetooth NAP connections.
+    - Fix multiple crashes. NetworkManager-1.58
+  + General:
+    - Unify the versioning to use everywhere the scheme with the
+      -rcX or -dev suffixes when appropriate. This affects, for
+      example, the URL and filename of the release tarball and the
+      version reported by nmcli and the daemon. As an exception,
+      the C API will continue to use the 90+ scheme for RC
+      versions.
+    - Install the systemd units in the initramfs using a systemd
+      generator.
+  + Core:
+    - Connection profiles with manual IP addressing and with
+      gateways that are not directly reachable will generate a
+      warning on activation and when they are added/modified via
+      nmcli and nmtui. NetworkManager currently adds on-link routes
+      for them automatically, but this will change in the future.
+      To fix the warning, users should add addresses or routes
+      whose subnets cover these gateways. A gateway (either the
+      default gateway or the next-hop of a route) is considered
+      directly reachable if it falls within the subnet of a direct
+      route (a route without a next hop) or of a prefix route from
+      a static address.
+    - Use an internal implementation of the ping functionality when
+      the "connection.gateway-ping-timeout" or
+      "connection.ip-ping-addresses" properties are set, instead of
+      relying on the "ping" tool.
+    - Add support for CLAT (464XLAT) using a BPF program,
+      controlled by the "ipv4.clat" property. CLAT is still
+      disabled by default for now.
+    - Change the default value of the ipv4.dhcp-ipv6-only-preferred
+      property to a new value "auto" which automatically enables
+      the option when CLAT is enabled ("yes" or "auto") in the
+      connection profile.
+    - Allow persisting the managed state across reboots from the
+      D-Bus API and nmcli. time as a change to the managed state
+      from the D-Bus API and nmcli.
+    - IPv6 interfaces that receive PD via DHCPv6 are considered
+      healthy without a non-temporary address. The delegated prefix
+      can be used via an interface configured with "ipv6.method:
+      shared"
+    - Fix reapply not honoring the ipv6.ignore-auto-dns,
+      ipv6.ignore-auto-routes and ipv6.never-default properties
+      when DHCPv6 was not restarted (for example when the IPv6 DNS
+      came from a DHCPv6 lease), so that DHCPv6-provided DNS and
+      routes are now correctly suppressed on reapply without a
+      connection restart.
+  + Connectivity:
+    - A new "check-connectivity" configuration option is available
+      to disable the connectivity check for selected interfaces.
+    - Restrict the connectivity check to use the DNS servers
+      defined on the same link. If the link has no DNS servers, the
+      connectivity check will use any servers available in the
+      system.
+    - Fix stale global connectivity state with connectivity
+      checking enabled: NetworkManager could report limited
+      connectivity while another device had full connectivity, or
+      keep reporting limited after a device regained internet
+      access.
+  + DHCP:
+    - The internal DHCPv4 client now ignores option 3 (Router) if
+      the lease contains option 121 (Classless Static Route), as
+      recommended by RFC 3442.
+    - Fix an out-of-bounds read in the internal DHCPv4 client that
+      an on-link attacker could trigger with a malformed UDP
+      packet, crashing NetworkManager.
+    - Validate hostnames and MUD URLs before pasting them into the
+      dhclient configuration file, rejecting characters that could
+      alter the config syntax (CVE-2026-10805).
+  + Wi-Fi:
+    - The "band" property of Wi-fi connections now accepts the
+      "6GHz" value.
+    - The powersave property now functions with the iwd backend.
+    - WIFI connections using wpa-psk respect the setting
+      connection.auth-retry and only prompt for new secrets during
+      the last authentication attempt before failing.
+    - Accept 64 hex-character PSK in WPS credentials which are
+      returned by some access points.
+    - When wpa_supplicant reports a WPA3-SAE password mismatch,
+      prompt the user for the password again instead of failing,
+      matching the WPA-PSK behavior.
+  + Nmtui / nmcli:
+    - Show the Wi-Fi band of APs in the scan results from nmcli.
+    - New <Select...> button in nmtui that allows users to chose
+      from list of available devices when creating connection
+      profiles for physical interfaces (Ethernet, Wi-Fi, etc.).
+    - Allow configuring all bond options in nmtui by introducing a
+      "other options" field, which covers options not already
+      covered by a dedicated input field.
+    - Nmtui now offers a "Show password" checkbox in the dialog
+      that prompts for secrets when activating a connection,
+      matching the connection editor.
+    - The nmtui connection lists ("nmtui connect" and "nmtui edit")
+      support a vim-style "/" search that filters the list to
+      matching entries as you type.
+    - The "Activate a connection" screen in nmtui now has a "Rescan
+      Wi-Fi" button that scans for nearby Wi-Fi networks on demand.
+    - Nmtui can now share a Wi-Fi connection as a QR code via the
+      "Share QR..." button in the "Edit a connection" view,
+      mirroring "nmcli device wifi show-password".
+    - Nmcli "connection show" now labels the ports column "PORT"
+      instead of "SLAVE" (the "SLAVE" field name is still accepted
+      as an alias), and adds the BRIDGE.PORTS, TEAM.PORTS and
+      GENERAL.CONTROLLER-PATH fields.
+    - Nmtui now redraws its forms when the terminal is resized,
+      instead of leaving them off-center or clipped until the form
+      is reopened.
+    - Nmcli "device wifi show-password" no longer prints a QR code
+      when the Wi-Fi password cannot be read due to insufficient
+      privileges; it prints a warning instead.
+  + VPN:
+    - Introduce a libnm function that can be used by VPN plugins to
+      check user permissions on certificate and keys.
+    - Fix VPN connections with "ipv4.dns-search" or
+      "ipv6.dns-search" set ignoring the search domains pushed by
+      the VPN; the manually configured and VPN-provided search
+      domains are now merged.
+  + Security:
+    - For private connections (the ones that specify a user in the
+      "connection.permissions" property), verify that the user can
+      access the 802.1X certificates and keys set in the
+      connection.
+    - Add a "polkit_noauth_group" build option to install a polkit
+      rule that lets admin users in the given group (typically
+      "sudo" or "wheel") make system-wide connection changes from a
+      local console without entering a password. It is empty
+      (disabled) by default and is discouraged.
+  + Deprecations and removals:
+    - The support for Wireless Extensions is deprecated and will be
+      removed in a future release. Wireless Extensions are now
+      disabled by default.
+    - Remove the modify_system build option that allowed setting up
+      the polkit permissions to allow non-admin users to create
+      system-wide connection. That configuration is discouraged
+      because it can be used to bypass filesystem permissions.
+    - Drop support for dhclient as a DHCP backend, which has been
+      deprecated since NetworkManager-1.50.
+    - Fix a bug that makes broadband connections auto-connect
+      getting blocked if the connection tries to reconnect when
+      modem status is
+- Drop 2308.patch: fixed upstream.
+- Drop 2312.patch: fixed upstream.
+- Drop 2462.patch: fixed upstream.
+- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
+- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
+- Rebase nm-add-CAP_SYS_ADMIN-permission.patch.
+- Drop -Ddhclient=%{_sbindir}/dhclient meson parameter: dhclient
+  has been deprecated since NM 1.50. Use internal dhcp client.
+- Add pkgconfig(libbpf), cross-bpf-gcc16, and bpftool
+  BuildRequires: new depencencies for CLAT (Customer-side
+  translator) support.
+
+-------------------------------------------------------------------

Old:
----
  2308.patch
  2312.patch
  2462.patch
  NetworkManager-1.56.1.tar.xz
  NetworkManager-CVE-2026-10805.patch
  NetworkManager-CVE-2026-19685.patch

New:
----
  NetworkManager-1.58.1.tar.xz

----------(Old B)----------
  Old:      modem status is
- Drop 2308.patch: fixed upstream.
- Drop 2312.patch: fixed upstream.
  Old:- Drop 2308.patch: fixed upstream.
- Drop 2312.patch: fixed upstream.
- Drop 2462.patch: fixed upstream.
  Old:- Drop 2312.patch: fixed upstream.
- Drop 2462.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
  Old:- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
- Rebase nm-add-CAP_SYS_ADMIN-permission.patch.
  Old:- Drop 2462.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ NetworkManager.spec ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old  2026-10-02 23:01:42.414183178 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new  2026-10-02 23:01:42.417183303 +0200
@@ -63,8 +63,15 @@
 %define libaudit_meson_opt no
 %endif
 
+# No BPF on i586
+%ifnarch %{ix86}
+%bcond_without bpf
+%else
+%bcond_with bpf
+%endif
+
 Name:           NetworkManager
-Version:        1.56.1
+Version:        1.58.1
 Release:        0
 Summary:        Standard Linux network configuration tool suite
 License:        GPL-2.0-or-later AND LGPL-2.1-or-later
@@ -98,18 +105,8 @@
 Patch9:         NetworkManager-dont-renew-bridge-dhcp-if-no-mac-on-wakeup.patch
 # PATCH-FIX-OPENSUSE nm-initrd-generator document static ip setup bsc#1244072
 Patch11:        0001-man-document-static-ip-setup-differences-to-dracut-n.patch
-# PATCH-FIX-UPSTREAM 
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2312.patch
-Patch13:        2312.patch
-# PATCH-FIX-UPSTREAM 
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2308.patch
-Patch14:        2308.patch
-# PATCH-FIX-UPSTREAM 2462.patch bsc#1259025, 
glfd#NetworkManager/NetworkManager!2462 [email protected] --  
nm-initrd-generator: set parent for NBFT vlan connection
-Patch15:        2462.patch
 # PATCH-FEATURE-SLE NetworkManager-initrd-generator-ip-hcn.patch PED-14534 
[email protected] -- handle "ip=hcn" option in nm-initrd-generator, it generates 
an empty connection
 Patch16:        NetworkManager-initrd-generator-ip-hcn.patch
-# PATCH-FIX-UPSTREAM NetworkManager-CVE-2026-10805.patch bsc#1267696, 
CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426 [email protected] --  
dhclient: reject unsafe characters in URLs and hostnames
-Patch17:        NetworkManager-CVE-2026-10805.patch
-# PATCH-FIX-UPSTREAM NetworkManager-CVE-2026-19685.patch bsc#1276764, 
CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513 [email protected] -- 
core: 802.1x: reject ca-path for private connections
-Patch18:        NetworkManager-CVE-2026-19685.patch
 
 BuildRequires:  c++_compiler
 BuildRequires:  dnsmasq
@@ -123,19 +120,19 @@
 BuildRequires:  rp-pppoe
 BuildRequires:  wireless-tools
 BuildRequires:  perl(YAML)
-BuildRequires:  pkgconfig(dbus-1)
+BuildRequires:  pkgconfig(dbus-1) >= 1.1
 BuildRequires:  pkgconfig(dbus-glib-1) >= 0.94
 BuildRequires:  pkgconfig(glib-2.0) >= 2.42
-BuildRequires:  pkgconfig(gobject-introspection-1.0)
+BuildRequires:  pkgconfig(gobject-introspection-1.0) >= 0.9.6
 BuildRequires:  pkgconfig(gtk-doc)
 BuildRequires:  pkgconfig(jansson) >= 2.7
-BuildRequires:  pkgconfig(libcurl)
-BuildRequires:  pkgconfig(libndp)
+BuildRequires:  pkgconfig(libcurl) >= 7.24.0
+BuildRequires:  pkgconfig(libndp) >= 1.9
 BuildRequires:  pkgconfig(libnewt) >= 0.52.15
 BuildRequires:  pkgconfig(libnl-3.0) >= 3.2.8
 BuildRequires:  pkgconfig(libnl-genl-3.0)
 BuildRequires:  pkgconfig(libnl-route-3.0)
-BuildRequires:  pkgconfig(libnvme)
+BuildRequires:  pkgconfig(libnvme) >= 1.5
 BuildRequires:  pkgconfig(libpsl) >= 0.1
 BuildRequires:  pkgconfig(libselinux)
 BuildRequires:  pkgconfig(libsystemd) >= 209
@@ -147,10 +144,15 @@
 BuildRequires:  pkgconfig(udev)
 BuildRequires:  pkgconfig(uuid)
 BuildRequires:  pkgconfig(vapigen)
+BuildRequires:  bpftool
 ### Conditional BRs
 %if %{with LIBAUDIT}
 BuildRequires:  pkgconfig(audit)
 %endif
+%if %{with bpf}
+BuildRequires:  pkgconfig(libbpf) >= 1.3.0
+BuildRequires:  cross-bpf-gcc%{?gcc_version}
+%endif
 ## Required for tests
 %if %{with TESTS}
 #BuildRequires:  python3-gobject
@@ -335,14 +337,9 @@
 %patch -P 9 -p1
 %endif
 %patch -P 11 -p1
-%patch -P 13 -p1
-%patch -P 14 -p1
-%patch -P 15 -p1
 %if 0%{?sle_version} && 0%{?sle_version} > 160000
 %patch -P 16 -p1
 %endif
-%patch -P 17 -p1
-%patch -P 18 -p1
 
 # Fix server.conf's location, to end up in %%{_defaultdocdir}/%%{name},
 # rather then %%{_datadir}/doc/%%{name}/examples:
@@ -376,7 +373,6 @@
 %endif
     -Dconfig_dhcp_default=internal \
     -Ddhcpcd=no \
-    -Ddhclient=%{_sbindir}/dhclient \
     -Ddocs=true \
     -Dtests=%{tests_meson_opt} \
     -Dmore_asserts=0 \
@@ -385,6 +381,11 @@
     -Db_lto=true \
     -Dsession_tracking=systemd \
     -Dsession_tracking_consolekit=false \
+%if %{with bpf}
+    -Dbpf-compiler=gcc \
+%else
+    -Dclat=false \
+%endif
     %{nil}
 %meson_build
 

++++++ NetworkManager-1.56.1.tar.xz -> NetworkManager-1.58.1.tar.xz ++++++
++++ 185826 lines of diff (skipped)

++++++ NetworkManager.obsinfo ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old  2026-10-02 23:01:45.219300455 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new  2026-10-02 23:01:45.225300706 +0200
@@ -1,5 +1,5 @@
 name: NetworkManager
-version: 1.56.1
-mtime: 1778754131
-commit: b829f838fc5d8c93437faa5db44a5396b67893de
+version: 1.58.1
+mtime: 1787326149
+commit: 7406dfbcc35beed79bf2734e3e7376ead320bd99
 

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old  2026-10-02 23:01:45.278302922 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new  2026-10-02 23:01:45.289303382 +0200
@@ -1,7 +1,7 @@
-mtime: 1788400178
-commit: d740b87e22f67cabf887bb5a120a5b0d248b0d4a87a7d433de5153a2982efe07
+mtime: 1790847577
+commit: 898e9456e8de176a77ccbdf016d1b344e6214eade15ed01857cfe69e3b076981
 url: https://src.opensuse.org/GNOME/NetworkManager
-revision: d740b87e22f67cabf887bb5a120a5b0d248b0d4a87a7d433de5153a2982efe07
+revision: 898e9456e8de176a77ccbdf016d1b344e6214eade15ed01857cfe69e3b076981
 trackingbranch: factory
 projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old  2026-10-02 23:01:45.352306016 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new  2026-10-02 23:01:45.365306560 +0200
@@ -3,7 +3,7 @@
   <service name="obs_scm" mode="manual">
     <param name="scm">git</param>
     <param 
name="url">https://gitlab.freedesktop.org/NetworkManager/NetworkManager.git</param>
-    <param name="revision">1.56.1</param>
+    <param name="revision">1.58.1</param>
     <param name="versionformat">@PARENT_TAG@+@TAG_OFFSET@</param>
     <param name="versionrewrite-pattern">([^+-]*)(\+0)?(-rc[12])?</param>
     <param name="versionrewrite-replacement">\1</param>

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-10-01 11:39:37.000000000 +0200
@@ -0,0 +1,5 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild
+osc-collab.*

++++++ nm-add-CAP_SYS_ADMIN-permission.patch ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old  2026-10-02 23:01:46.003333234 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new  2026-10-02 23:01:46.011333569 +0200
@@ -1,14 +1,14 @@
-Index: NetworkManager-1.50.0/data/NetworkManager.service.in
-===================================================================
---- NetworkManager-1.50.0.orig/data/NetworkManager.service.in
-+++ NetworkManager-1.50.0/data/NetworkManager.service.in
+diff --git a/data/NetworkManager.service.in b/data/NetworkManager.service.in
+index b27b8d2dd8..cc90c52d0e 100644
+--- a/data/NetworkManager.service.in
++++ b/data/NetworkManager.service.in
 @@ -19,7 +19,7 @@ KillMode=process
  # With a huge number of interfaces, starting can take a long time.
  TimeoutStartSec=600
- 
+
 -CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_BPF 
CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE 
CAP_KILL CAP_SYS_CHROOT
 +CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_BPF 
CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE 
CAP_KILL CAP_SYS_CHROOT CAP_SYS_ADMIN
- 
- ProtectSystem=true
- ProtectHome=read-only
+
+ PrivateTmp=true
+
 

Reply via email to