Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-sglang for openSUSE:Factory checked in at 2026-10-02 23:05:11 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-sglang (Old) and /work/SRC/openSUSE:Factory/.python-sglang.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-sglang" Fri Oct 2 23:05:11 2026 rev:6 rq:1382074 version:0.5.21 Changes: -------- --- /work/SRC/openSUSE:Factory/python-sglang/python-sglang.changes 2026-10-01 16:47:08.457281890 +0200 +++ /work/SRC/openSUSE:Factory/.python-sglang.new.1631729/python-sglang.changes 2026-10-02 23:06:29.378191997 +0200 @@ -1,0 +2,38 @@ +Fri Oct 2 09:09:32 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 0.5.21: + * Prefill/decode disaggregation switches roles at runtime, the + unified radix cache runs on the Rust core by default + (SGLANG_UNIFIED_RADIX_TREE_CORE_BACKEND=python forces the + Python one), and /v1/decisions and /v1/score are new routes + * A chat_template in chat_template_kwargs is rejected unless + the server runs with --trust-request-chat-template + * Endpoints and env vars deprecated two releases ago are gone + (/model_info replaces /get_weight_version, /v1/loads replaces + /get_load), as are the legacy radix cache implementations + * A CustomLogitProcessor must return full-shape logits, and the + RL weight updates must run inside begin_weight_update() .. + end_weight_update() + * CPU dependency floors rise to torch 2.14.0, torchvision + 0.29.0, xgrammar 0.2.7, sentencepiece 0.2.1 and SoundFile + 0.13.1, and regex is a new runtime dep +- CVE-2026-86793: upstream 0.5.21 carries the SafeUnpickler fix + itself, so the two backports are dropped (boo#1280091) + * sglang-safe-unpickler-stdlib-globals.patch + * sglang-safe-unpickler-explicit-globals.patch +- CVE-2026-102634 stays carried: upstream PR 40185 is still + unmerged, so rebase sglang-40185-bootstrap-room-dedup.patch for + the reshuffled disaggregation files. Its CommonKVManager path + stays unreachable here - only the mooncake, mori and nixl + managers construct one, and no KV transfer transport library is + packaged (boo#1283270) +- Rebase sglang-relax-cpu-requirements.patch for the new floors +- Upstream holds sentencepiece at 0.2.1 because 0.2.2 rejects + null pieces in InternVL tokenizers, but Factory ships only + 0.2.2, so the floor here does not exclude it +- Regenerate vendor.tar.zst; the rust workspace gains + sglang-renderer and prost-types + * Many more fixes and improvements; see upstream's release + notes for the full list + +------------------------------------------------------------------- Old: ---- sglang-0.5.20.tar.gz sglang-safe-unpickler-explicit-globals.patch sglang-safe-unpickler-stdlib-globals.patch New: ---- sglang-0.5.21.tar.gz ----------(Old B)---------- Old: * sglang-safe-unpickler-stdlib-globals.patch * sglang-safe-unpickler-explicit-globals.patch - CVE-2026-102634 stays carried: upstream PR 40185 is still Old: itself, so the two backports are dropped (boo#1280091) * sglang-safe-unpickler-stdlib-globals.patch * sglang-safe-unpickler-explicit-globals.patch ----------(Old E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-sglang.spec ++++++ --- /var/tmp/diff_new_pack.Cy6i1w/_old 2026-10-02 23:06:46.925931070 +0200 +++ /var/tmp/diff_new_pack.Cy6i1w/_new 2026-10-02 23:06:46.928931196 +0200 @@ -17,7 +17,7 @@ Name: python-sglang -Version: 0.5.20 +Version: 0.5.21 Release: 0 Summary: Fast serving framework for large language models # Legal-Review-Notice: sgl-model-gateway and CUDA AOT kernels @@ -48,15 +48,11 @@ Patch2: sglang-cpu-rust-exts.patch # PATCH-FIX-OPENSUSE sglang-grpc-system-protoc.patch -- use system protoc instead of protoc-bin-vendored Patch3: sglang-grpc-system-protoc.patch -# PATCH-FIX-UPSTREAM sglang-safe-unpickler-stdlib-globals.patch boo#1280091 -- CVE-2026-86793: sgl-project/sglang commit 882577451e (PR 39858), replace SafeUnpickler's standard-library module prefixes with exact globals -Patch4: sglang-safe-unpickler-stdlib-globals.patch -# PATCH-FIX-UPSTREAM sglang-safe-unpickler-explicit-globals.patch boo#1280091 -- CVE-2026-86793: sgl-project/sglang commit 5b42d10edf (PR 40259), drop the remaining module prefixes and route torch.storage._load_from_bytes through a weights_only torch.load -Patch5: sglang-safe-unpickler-explicit-globals.patch -# PATCH-FIX-UPSTREAM sglang-40185-bootstrap-room-dedup.patch boo#1283270 -- CVE-2026-102634: sgl-project/sglang PR 40185 (unmerged, head commit 1901ddecfe), report an unknown bootstrap_room as KVPoll.Failed instead of letting check_status raise KeyError, and count KVPoll.Success as bootstrap-done; 2 of the PR's 27 files, the rest being a typing modernisation that does not apply to 0.5.20 -Patch6: sglang-40185-bootstrap-room-dedup.patch +# PATCH-FIX-UPSTREAM sglang-40185-bootstrap-room-dedup.patch boo#1283270 -- CVE-2026-102634: sgl-project/sglang PR 40185 (unmerged, head commit 1901ddecfe), report an unknown bootstrap_room as KVPoll.Failed instead of letting check_status raise KeyError, and count KVPoll.Success as bootstrap-done; 2 of the PR's 27 files, the rest being a typing modernisation that does not apply to 0.5.21 +Patch4: sglang-40185-bootstrap-room-dedup.patch BuildRequires: %{python_module IPython} BuildRequires: %{python_module Pillow} -BuildRequires: %{python_module SoundFile} +BuildRequires: %{python_module SoundFile >= 0.13.1} BuildRequires: %{python_module aiohttp} BuildRequires: %{python_module anthropic >= 0.20.0} BuildRequires: %{python_module blobfile >= 3.0.0} @@ -85,9 +81,10 @@ BuildRequires: %{python_module pydantic} BuildRequires: %{python_module python-multipart} BuildRequires: %{python_module pyzmq >= 25.1.2} +BuildRequires: %{python_module regex} BuildRequires: %{python_module requests} BuildRequires: %{python_module scipy} -BuildRequires: %{python_module sentencepiece} +BuildRequires: %{python_module sentencepiece >= 0.2.1} BuildRequires: %{python_module setproctitle} BuildRequires: %{python_module setuptools >= 61.0} BuildRequires: %{python_module setuptools-rust >= 1.10} @@ -95,15 +92,15 @@ BuildRequires: %{python_module tabulate} BuildRequires: %{python_module tiktoken} BuildRequires: %{python_module timm >= 1.0.16} -BuildRequires: %{python_module torch >= 2.12.0} +BuildRequires: %{python_module torch >= 2.14.0} BuildRequires: %{python_module torchaudio >= 2.11.0} -BuildRequires: %{python_module torchvision >= 0.27.0} +BuildRequires: %{python_module torchvision >= 0.29.0} BuildRequires: %{python_module tqdm} BuildRequires: %{python_module transformers >= 5.12.1} BuildRequires: %{python_module uvicorn} BuildRequires: %{python_module uvloop} BuildRequires: %{python_module wheel} -BuildRequires: %{python_module xgrammar >= 0.2.1} +BuildRequires: %{python_module xgrammar >= 0.2.7} BuildRequires: %{python_module xxhash} BuildRequires: %{python_module zstandard} BuildRequires: alts @@ -123,7 +120,7 @@ # METADATA, so these manual Requires are load-bearing. Requires: alts Requires: python-Pillow -Requires: python-SoundFile +Requires: python-SoundFile >= 0.13.1 Requires: python-aiohttp Requires: python-anthropic >= 0.20.0 Requires: python-blobfile >= 3.0.0 @@ -151,21 +148,22 @@ Requires: python-pydantic Requires: python-python-multipart Requires: python-pyzmq >= 25.1.2 +Requires: python-regex Requires: python-requests Requires: python-scipy -Requires: python-sentencepiece +Requires: python-sentencepiece >= 0.2.1 Requires: python-setproctitle Requires: python-tabulate Requires: python-tiktoken Requires: python-timm >= 1.0.16 -Requires: python-torch >= 2.12.0 +Requires: python-torch >= 2.14.0 Requires: python-torchaudio >= 2.11.0 -Requires: python-torchvision >= 0.27.0 +Requires: python-torchvision >= 0.29.0 Requires: python-tqdm Requires: python-transformers >= 5.12.1 Requires: python-uvicorn Requires: python-uvloop -Requires: python-xgrammar >= 0.2.1 +Requires: python-xgrammar >= 0.2.7 Requires: python-xxhash Requires: python-zstandard # outlines 0.1.11 needs outlines_core 0.1.26 (fsm.guide); Factory/s:ml ++++++ sglang-0.5.20.tar.gz -> sglang-0.5.21.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-sglang/sglang-0.5.20.tar.gz /work/SRC/openSUSE:Factory/.python-sglang.new.1631729/sglang-0.5.21.tar.gz differ: char 13, line 1 ++++++ sglang-40185-bootstrap-room-dedup.patch ++++++ --- /var/tmp/diff_new_pack.Cy6i1w/_old 2026-10-02 23:06:47.181941852 +0200 +++ /var/tmp/diff_new_pack.Cy6i1w/_new 2026-10-02 23:06:47.190942231 +0200 @@ -11,7 +11,7 @@ 1901ddecfebb5960bebcb237efb96397b85be355, tracking issue 40125, both still open). Only the two behavioural hunks of that PR are carried here. Its other 25 files are a PEP 604 typing modernisation plus import shuffling, which -does not apply cleanly to the 0.5.20 tag and is not part of this fix. +does not apply cleanly to the 0.5.21 tag and is not part of this fix. * check_status() reports an unregistered room as KVPoll.Failed instead of raising KeyError. KVPoll.Failed is already handled by DecodePreallocQueue, @@ -26,12 +26,11 @@ python/sglang/srt/disaggregation/common/conn.py | 2 +- python/sglang/srt/disaggregation/decode.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) - diff --git a/python/sglang/srt/disaggregation/common/conn.py b/python/sglang/srt/disaggregation/common/conn.py --- a/python/sglang/srt/disaggregation/common/conn.py +++ b/python/sglang/srt/disaggregation/common/conn.py -@@ -390,7 +390,7 @@ - ) +@@ -410,7 +410,7 @@ + self._dcp_pack_max_tokens = max_tokens def check_status(self, bootstrap_room: int) -> KVPoll: - return self.request_status[bootstrap_room] @@ -42,7 +41,7 @@ diff --git a/python/sglang/srt/disaggregation/decode.py b/python/sglang/srt/disaggregation/decode.py --- a/python/sglang/srt/disaggregation/decode.py +++ b/python/sglang/srt/disaggregation/decode.py -@@ -915,7 +915,7 @@ +@@ -1050,7 +1050,7 @@ if poll == KVPoll.Bootstrapping: pass ++++++ sglang-relax-cpu-requirements.patch ++++++ --- /var/tmp/diff_new_pack.Cy6i1w/_old 2026-10-02 23:06:47.261945222 +0200 +++ /var/tmp/diff_new_pack.Cy6i1w/_new 2026-10-02 23:06:47.277945896 +0200 @@ -38,7 +38,7 @@ "orjson", "outlines", "packaging", -@@ -45,32 +42,27 @@ +@@ -45,33 +42,28 @@ "pillow", "prometheus-client>=0.20.0", "psutil", @@ -48,9 +48,11 @@ "python-multipart", - "pytest", "pyzmq>=25.1.2", + "regex", "requests", "scipy", - "sentencepiece", +- "sentencepiece==0.2.1", # 0.2.2 rejects null pieces in InternVL tokenizers. ++ "sentencepiece>=0.2.1", # 0.2.2 rejects null pieces in InternVL tokenizers. "setproctitle", - "smg-grpc-servicer>=0.9.0", - "soundfile==0.13.1", @@ -58,27 +60,27 @@ "tabulate", "tiktoken", - "timm==1.0.16", -- "torch==2.12.0", +- "torch==2.14.0", - "torchaudio==2.11.0", - "torchcodec==0.12.0 ; sys_platform != 'linux' or (sys_platform == 'linux' and platform_machine != 'aarch64' and platform_machine != 'arm64' and platform_machine != 'armv7l')", -- "torchvision==0.27.0", +- "torchvision==0.29.0", + "timm>=1.0.16", -+ "torch>=2.12.0", ++ "torch>=2.14.0", + "torchaudio>=2.11.0", -+ "torchvision>=0.27.0", ++ "torchvision>=0.29.0", "tqdm", - "transformers==5.12.1", -- "triton==3.7.0", +- "triton==3.8.0", + "transformers>=5.12.1", "uvicorn", "uvloop", "xxhash", -- "xgrammar==0.2.1", -+ "xgrammar>=0.2.1", +- "xgrammar==0.2.7", ++ "xgrammar>=0.2.7", "zstandard", ] -@@ -128,6 +120,12 @@ +@@ -129,6 +121,12 @@ "kernels/**/*" ] @@ -91,7 +93,7 @@ [tool.setuptools.packages.find] exclude = [ "assets*", -@@ -136,6 +134,8 @@ +@@ -137,6 +135,8 @@ "dist*", "playground*", "scripts*", @@ -100,7 +102,7 @@ "tests*", ] -@@ -147,6 +147,8 @@ +@@ -148,6 +148,8 @@ "dist*", "playground*", "scripts*", ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/python-sglang/vendor.tar.zst /work/SRC/openSUSE:Factory/.python-sglang.new.1631729/vendor.tar.zst differ: char 7, line 1
