Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package NetworkManager for openSUSE:Factory
checked in at 2026-10-02 23:01:21
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/NetworkManager (Old)
and /work/SRC/openSUSE:Factory/.NetworkManager.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "NetworkManager"
Fri Oct 2 23:01:21 2026 rev:296 rq:1381857 version:1.58.1
Changes:
--------
--- /work/SRC/openSUSE:Factory/NetworkManager/NetworkManager.changes
2026-09-07 11:26:29.696018505 +0200
+++
/work/SRC/openSUSE:Factory/.NetworkManager.new.1631729/NetworkManager.changes
2026-10-02 23:01:40.882119125 +0200
@@ -1,0 +2,192 @@
+Thu Oct 1 09:37:50 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Disable 464XLAT Customer-side Translator (CLAT) support on %ix86:
+ + Introduce bcond_with/withot bpf build condition, based on arch
+ + Pass -Dclat=false to meson when bpf is disabled
+ + Only conditionally BuildRequire libbpf and cross-bpf-gcc
+
+-------------------------------------------------------------------
+Wed Sep 30 15:07:29 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update version dependencies according to meson.build.
+
+-------------------------------------------------------------------
+Thu Sep 24 12:50:31 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update to version 1.58.1:
+ + Overview of changes since NetworkManager-1.58.0:
+ - For private connections (the ones that specify a user in the
+ "connection.permissions" property), the 802.1X "ca-path" and
+ "phase2-ca-path" properties are no longer accepted and
+ activation fails, as the daemon would otherwise let the owner
+ of the profile choose the CA trust store used to validate the
+ authentication server. Such profiles must clear those
+ properties and use "ca-cert" or "system-ca-certs" instead.
+ - Fix IPv4 forwarding not enabled on modem data interfaces.
+ - Log a warning when ignoring DHCPv4 option 3 (Router) due to
+ the presence of option 121/249 (Classless Static Routes)
+ results in no gateway.
+ - Set the parent interface by name for NBFT VLAN connections in
+ the initrd generator to avoid race conditions at boot.
+ - Perform the connectivity check also when the interface only
+ has an IPv4 link-scope default route.
+ - Ignore unspecified addresses as DNS nameservers from RDNSS
+ and DHCPv6, and skip invalid nameservers when configuring
+ systemd-resolved.
+ - Fix auto-connect to SAE (WPA3) networks with key-mgmt=wpa-psk
+ profiles.
+ - Fix DNS server port number not forwarded to systemd-resolved
+ for DNS URIs.
+ - Fix normalization of Bluetooth NAP connections.
+ - Fix multiple crashes. NetworkManager-1.58
+ + General:
+ - Unify the versioning to use everywhere the scheme with the
+ -rcX or -dev suffixes when appropriate. This affects, for
+ example, the URL and filename of the release tarball and the
+ version reported by nmcli and the daemon. As an exception,
+ the C API will continue to use the 90+ scheme for RC
+ versions.
+ - Install the systemd units in the initramfs using a systemd
+ generator.
+ + Core:
+ - Connection profiles with manual IP addressing and with
+ gateways that are not directly reachable will generate a
+ warning on activation and when they are added/modified via
+ nmcli and nmtui. NetworkManager currently adds on-link routes
+ for them automatically, but this will change in the future.
+ To fix the warning, users should add addresses or routes
+ whose subnets cover these gateways. A gateway (either the
+ default gateway or the next-hop of a route) is considered
+ directly reachable if it falls within the subnet of a direct
+ route (a route without a next hop) or of a prefix route from
+ a static address.
+ - Use an internal implementation of the ping functionality when
+ the "connection.gateway-ping-timeout" or
+ "connection.ip-ping-addresses" properties are set, instead of
+ relying on the "ping" tool.
+ - Add support for CLAT (464XLAT) using a BPF program,
+ controlled by the "ipv4.clat" property. CLAT is still
+ disabled by default for now.
+ - Change the default value of the ipv4.dhcp-ipv6-only-preferred
+ property to a new value "auto" which automatically enables
+ the option when CLAT is enabled ("yes" or "auto") in the
+ connection profile.
+ - Allow persisting the managed state across reboots from the
+ D-Bus API and nmcli. time as a change to the managed state
+ from the D-Bus API and nmcli.
+ - IPv6 interfaces that receive PD via DHCPv6 are considered
+ healthy without a non-temporary address. The delegated prefix
+ can be used via an interface configured with "ipv6.method:
+ shared"
+ - Fix reapply not honoring the ipv6.ignore-auto-dns,
+ ipv6.ignore-auto-routes and ipv6.never-default properties
+ when DHCPv6 was not restarted (for example when the IPv6 DNS
+ came from a DHCPv6 lease), so that DHCPv6-provided DNS and
+ routes are now correctly suppressed on reapply without a
+ connection restart.
+ + Connectivity:
+ - A new "check-connectivity" configuration option is available
+ to disable the connectivity check for selected interfaces.
+ - Restrict the connectivity check to use the DNS servers
+ defined on the same link. If the link has no DNS servers, the
+ connectivity check will use any servers available in the
+ system.
+ - Fix stale global connectivity state with connectivity
+ checking enabled: NetworkManager could report limited
+ connectivity while another device had full connectivity, or
+ keep reporting limited after a device regained internet
+ access.
+ + DHCP:
+ - The internal DHCPv4 client now ignores option 3 (Router) if
+ the lease contains option 121 (Classless Static Route), as
+ recommended by RFC 3442.
+ - Fix an out-of-bounds read in the internal DHCPv4 client that
+ an on-link attacker could trigger with a malformed UDP
+ packet, crashing NetworkManager.
+ - Validate hostnames and MUD URLs before pasting them into the
+ dhclient configuration file, rejecting characters that could
+ alter the config syntax (CVE-2026-10805).
+ + Wi-Fi:
+ - The "band" property of Wi-fi connections now accepts the
+ "6GHz" value.
+ - The powersave property now functions with the iwd backend.
+ - WIFI connections using wpa-psk respect the setting
+ connection.auth-retry and only prompt for new secrets during
+ the last authentication attempt before failing.
+ - Accept 64 hex-character PSK in WPS credentials which are
+ returned by some access points.
+ - When wpa_supplicant reports a WPA3-SAE password mismatch,
+ prompt the user for the password again instead of failing,
+ matching the WPA-PSK behavior.
+ + Nmtui / nmcli:
+ - Show the Wi-Fi band of APs in the scan results from nmcli.
+ - New <Select...> button in nmtui that allows users to chose
+ from list of available devices when creating connection
+ profiles for physical interfaces (Ethernet, Wi-Fi, etc.).
+ - Allow configuring all bond options in nmtui by introducing a
+ "other options" field, which covers options not already
+ covered by a dedicated input field.
+ - Nmtui now offers a "Show password" checkbox in the dialog
+ that prompts for secrets when activating a connection,
+ matching the connection editor.
+ - The nmtui connection lists ("nmtui connect" and "nmtui edit")
+ support a vim-style "/" search that filters the list to
+ matching entries as you type.
+ - The "Activate a connection" screen in nmtui now has a "Rescan
+ Wi-Fi" button that scans for nearby Wi-Fi networks on demand.
+ - Nmtui can now share a Wi-Fi connection as a QR code via the
+ "Share QR..." button in the "Edit a connection" view,
+ mirroring "nmcli device wifi show-password".
+ - Nmcli "connection show" now labels the ports column "PORT"
+ instead of "SLAVE" (the "SLAVE" field name is still accepted
+ as an alias), and adds the BRIDGE.PORTS, TEAM.PORTS and
+ GENERAL.CONTROLLER-PATH fields.
+ - Nmtui now redraws its forms when the terminal is resized,
+ instead of leaving them off-center or clipped until the form
+ is reopened.
+ - Nmcli "device wifi show-password" no longer prints a QR code
+ when the Wi-Fi password cannot be read due to insufficient
+ privileges; it prints a warning instead.
+ + VPN:
+ - Introduce a libnm function that can be used by VPN plugins to
+ check user permissions on certificate and keys.
+ - Fix VPN connections with "ipv4.dns-search" or
+ "ipv6.dns-search" set ignoring the search domains pushed by
+ the VPN; the manually configured and VPN-provided search
+ domains are now merged.
+ + Security:
+ - For private connections (the ones that specify a user in the
+ "connection.permissions" property), verify that the user can
+ access the 802.1X certificates and keys set in the
+ connection.
+ - Add a "polkit_noauth_group" build option to install a polkit
+ rule that lets admin users in the given group (typically
+ "sudo" or "wheel") make system-wide connection changes from a
+ local console without entering a password. It is empty
+ (disabled) by default and is discouraged.
+ + Deprecations and removals:
+ - The support for Wireless Extensions is deprecated and will be
+ removed in a future release. Wireless Extensions are now
+ disabled by default.
+ - Remove the modify_system build option that allowed setting up
+ the polkit permissions to allow non-admin users to create
+ system-wide connection. That configuration is discouraged
+ because it can be used to bypass filesystem permissions.
+ - Drop support for dhclient as a DHCP backend, which has been
+ deprecated since NetworkManager-1.50.
+ - Fix a bug that makes broadband connections auto-connect
+ getting blocked if the connection tries to reconnect when
+ modem status is
+- Drop 2308.patch: fixed upstream.
+- Drop 2312.patch: fixed upstream.
+- Drop 2462.patch: fixed upstream.
+- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
+- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
+- Rebase nm-add-CAP_SYS_ADMIN-permission.patch.
+- Drop -Ddhclient=%{_sbindir}/dhclient meson parameter: dhclient
+ has been deprecated since NM 1.50. Use internal dhcp client.
+- Add pkgconfig(libbpf), cross-bpf-gcc16, and bpftool
+ BuildRequires: new depencencies for CLAT (Customer-side
+ translator) support.
+
+-------------------------------------------------------------------
Old:
----
2308.patch
2312.patch
2462.patch
NetworkManager-1.56.1.tar.xz
NetworkManager-CVE-2026-10805.patch
NetworkManager-CVE-2026-19685.patch
New:
----
NetworkManager-1.58.1.tar.xz
----------(Old B)----------
Old: modem status is
- Drop 2308.patch: fixed upstream.
- Drop 2312.patch: fixed upstream.
Old:- Drop 2308.patch: fixed upstream.
- Drop 2312.patch: fixed upstream.
- Drop 2462.patch: fixed upstream.
Old:- Drop 2312.patch: fixed upstream.
- Drop 2462.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
Old:- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
- Rebase nm-add-CAP_SYS_ADMIN-permission.patch.
Old:- Drop 2462.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-19685.patch: fixed upstream.
- Drop NetworkManager-CVE-2026-10805.patch: fixed upstream.
----------(Old E)----------
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ NetworkManager.spec ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old 2026-10-02 23:01:42.414183178 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new 2026-10-02 23:01:42.417183303 +0200
@@ -63,8 +63,15 @@
%define libaudit_meson_opt no
%endif
+# No BPF on i586
+%ifnarch %{ix86}
+%bcond_without bpf
+%else
+%bcond_with bpf
+%endif
+
Name: NetworkManager
-Version: 1.56.1
+Version: 1.58.1
Release: 0
Summary: Standard Linux network configuration tool suite
License: GPL-2.0-or-later AND LGPL-2.1-or-later
@@ -98,18 +105,8 @@
Patch9: NetworkManager-dont-renew-bridge-dhcp-if-no-mac-on-wakeup.patch
# PATCH-FIX-OPENSUSE nm-initrd-generator document static ip setup bsc#1244072
Patch11: 0001-man-document-static-ip-setup-differences-to-dracut-n.patch
-# PATCH-FIX-UPSTREAM
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2312.patch
-Patch13: 2312.patch
-# PATCH-FIX-UPSTREAM
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2308.patch
-Patch14: 2308.patch
-# PATCH-FIX-UPSTREAM 2462.patch bsc#1259025,
glfd#NetworkManager/NetworkManager!2462 [email protected] --
nm-initrd-generator: set parent for NBFT vlan connection
-Patch15: 2462.patch
# PATCH-FEATURE-SLE NetworkManager-initrd-generator-ip-hcn.patch PED-14534
[email protected] -- handle "ip=hcn" option in nm-initrd-generator, it generates
an empty connection
Patch16: NetworkManager-initrd-generator-ip-hcn.patch
-# PATCH-FIX-UPSTREAM NetworkManager-CVE-2026-10805.patch bsc#1267696,
CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426 [email protected] --
dhclient: reject unsafe characters in URLs and hostnames
-Patch17: NetworkManager-CVE-2026-10805.patch
-# PATCH-FIX-UPSTREAM NetworkManager-CVE-2026-19685.patch bsc#1276764,
CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513 [email protected] --
core: 802.1x: reject ca-path for private connections
-Patch18: NetworkManager-CVE-2026-19685.patch
BuildRequires: c++_compiler
BuildRequires: dnsmasq
@@ -123,19 +120,19 @@
BuildRequires: rp-pppoe
BuildRequires: wireless-tools
BuildRequires: perl(YAML)
-BuildRequires: pkgconfig(dbus-1)
+BuildRequires: pkgconfig(dbus-1) >= 1.1
BuildRequires: pkgconfig(dbus-glib-1) >= 0.94
BuildRequires: pkgconfig(glib-2.0) >= 2.42
-BuildRequires: pkgconfig(gobject-introspection-1.0)
+BuildRequires: pkgconfig(gobject-introspection-1.0) >= 0.9.6
BuildRequires: pkgconfig(gtk-doc)
BuildRequires: pkgconfig(jansson) >= 2.7
-BuildRequires: pkgconfig(libcurl)
-BuildRequires: pkgconfig(libndp)
+BuildRequires: pkgconfig(libcurl) >= 7.24.0
+BuildRequires: pkgconfig(libndp) >= 1.9
BuildRequires: pkgconfig(libnewt) >= 0.52.15
BuildRequires: pkgconfig(libnl-3.0) >= 3.2.8
BuildRequires: pkgconfig(libnl-genl-3.0)
BuildRequires: pkgconfig(libnl-route-3.0)
-BuildRequires: pkgconfig(libnvme)
+BuildRequires: pkgconfig(libnvme) >= 1.5
BuildRequires: pkgconfig(libpsl) >= 0.1
BuildRequires: pkgconfig(libselinux)
BuildRequires: pkgconfig(libsystemd) >= 209
@@ -147,10 +144,15 @@
BuildRequires: pkgconfig(udev)
BuildRequires: pkgconfig(uuid)
BuildRequires: pkgconfig(vapigen)
+BuildRequires: bpftool
### Conditional BRs
%if %{with LIBAUDIT}
BuildRequires: pkgconfig(audit)
%endif
+%if %{with bpf}
+BuildRequires: pkgconfig(libbpf) >= 1.3.0
+BuildRequires: cross-bpf-gcc%{?gcc_version}
+%endif
## Required for tests
%if %{with TESTS}
#BuildRequires: python3-gobject
@@ -335,14 +337,9 @@
%patch -P 9 -p1
%endif
%patch -P 11 -p1
-%patch -P 13 -p1
-%patch -P 14 -p1
-%patch -P 15 -p1
%if 0%{?sle_version} && 0%{?sle_version} > 160000
%patch -P 16 -p1
%endif
-%patch -P 17 -p1
-%patch -P 18 -p1
# Fix server.conf's location, to end up in %%{_defaultdocdir}/%%{name},
# rather then %%{_datadir}/doc/%%{name}/examples:
@@ -376,7 +373,6 @@
%endif
-Dconfig_dhcp_default=internal \
-Ddhcpcd=no \
- -Ddhclient=%{_sbindir}/dhclient \
-Ddocs=true \
-Dtests=%{tests_meson_opt} \
-Dmore_asserts=0 \
@@ -385,6 +381,11 @@
-Db_lto=true \
-Dsession_tracking=systemd \
-Dsession_tracking_consolekit=false \
+%if %{with bpf}
+ -Dbpf-compiler=gcc \
+%else
+ -Dclat=false \
+%endif
%{nil}
%meson_build
++++++ NetworkManager-1.56.1.tar.xz -> NetworkManager-1.58.1.tar.xz ++++++
++++ 185826 lines of diff (skipped)
++++++ NetworkManager.obsinfo ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old 2026-10-02 23:01:45.219300455 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new 2026-10-02 23:01:45.225300706 +0200
@@ -1,5 +1,5 @@
name: NetworkManager
-version: 1.56.1
-mtime: 1778754131
-commit: b829f838fc5d8c93437faa5db44a5396b67893de
+version: 1.58.1
+mtime: 1787326149
+commit: 7406dfbcc35beed79bf2734e3e7376ead320bd99
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old 2026-10-02 23:01:45.278302922 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new 2026-10-02 23:01:45.289303382 +0200
@@ -1,7 +1,7 @@
-mtime: 1788400178
-commit: d740b87e22f67cabf887bb5a120a5b0d248b0d4a87a7d433de5153a2982efe07
+mtime: 1790847577
+commit: 898e9456e8de176a77ccbdf016d1b344e6214eade15ed01857cfe69e3b076981
url: https://src.opensuse.org/GNOME/NetworkManager
-revision: d740b87e22f67cabf887bb5a120a5b0d248b0d4a87a7d433de5153a2982efe07
+revision: 898e9456e8de176a77ccbdf016d1b344e6214eade15ed01857cfe69e3b076981
trackingbranch: factory
projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj
++++++ _service ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old 2026-10-02 23:01:45.352306016 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new 2026-10-02 23:01:45.365306560 +0200
@@ -3,7 +3,7 @@
<service name="obs_scm" mode="manual">
<param name="scm">git</param>
<param
name="url">https://gitlab.freedesktop.org/NetworkManager/NetworkManager.git</param>
- <param name="revision">1.56.1</param>
+ <param name="revision">1.58.1</param>
<param name="versionformat">@PARENT_TAG@+@TAG_OFFSET@</param>
<param name="versionrewrite-pattern">([^+-]*)(\+0)?(-rc[12])?</param>
<param name="versionrewrite-replacement">\1</param>
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-10-01 11:39:37.000000000 +0200
@@ -0,0 +1,5 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild
+osc-collab.*
++++++ nm-add-CAP_SYS_ADMIN-permission.patch ++++++
--- /var/tmp/diff_new_pack.pSxixW/_old 2026-10-02 23:01:46.003333234 +0200
+++ /var/tmp/diff_new_pack.pSxixW/_new 2026-10-02 23:01:46.011333569 +0200
@@ -1,14 +1,14 @@
-Index: NetworkManager-1.50.0/data/NetworkManager.service.in
-===================================================================
---- NetworkManager-1.50.0.orig/data/NetworkManager.service.in
-+++ NetworkManager-1.50.0/data/NetworkManager.service.in
+diff --git a/data/NetworkManager.service.in b/data/NetworkManager.service.in
+index b27b8d2dd8..cc90c52d0e 100644
+--- a/data/NetworkManager.service.in
++++ b/data/NetworkManager.service.in
@@ -19,7 +19,7 @@ KillMode=process
# With a huge number of interfaces, starting can take a long time.
TimeoutStartSec=600
-
+
-CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_BPF
CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE
CAP_KILL CAP_SYS_CHROOT
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_BPF
CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE
CAP_KILL CAP_SYS_CHROOT CAP_SYS_ADMIN
-
- ProtectSystem=true
- ProtectHome=read-only
+
+ PrivateTmp=true
+