Packages changed: aws-lc (1.54.0 -> 1.56.0) checkpolicy (3.8.1 -> 3.9) firewalld hplip libquicktime libselinux (3.8.1 -> 3.9) libselinux-bindings (3.8.1 -> 3.9) libsemanage (3.8.1 -> 3.9) libsepol (3.8.1 -> 3.9) libzypp (17.37.12 -> 17.37.14) lttng-ust ncompress openSUSE-build-key patterns-xfce policycoreutils (3.8.1 -> 3.9) python-semanage (3.8.1 -> 3.9) qemu xf86-video-voodoo === Details === ==== aws-lc ==== Version update (1.54.0 -> 1.56.0) - update to version 1.56.0: * Export BIO_f_md for consumers * Remove obsolete python main patch * Remove redundant conditions * Implement pkcs8 cli * Export BF_cfb64_encrypt * Add pkey command to CLI tool * Improve OpenSSL compatibility * Fix PKCS12 Error Code * Use SP 800-56Arev3 Section 5.6.2.1.4.b instead of ECDSA PCT method * Minimize the nginx patch even further * Add LC contributors to allowlist * Align -help return codes in tool-openssl CLI to match Openssl * Dynamically link AWS-LC in cpython integration tests * Add missing x509 CI to list of tests * docs: Add FIPS documentation to BUILDING.md and README.md * Implement SSL_CTX_set_client_hello_cb for ClientHello callback * tool-openssl: Fix warning 'strnlen' specified bound 4096 exceeds source size 128 * Pull in SSL_get_negotiated_group and TLSEXT_nid_unknown from upstream * Document non-support of TLS 1.3 - update to version 1.55.0: * Add SSL_CTRL defines for SSL_*_tlsext_status_type * Implement HMAC over SHA3 truncated variants * Temporarily allowlist the webhook actors to AWS-LC * Rework memory BIOs and implement BIO_seek * s2n-bignum: Add prefix header to _s2n_bignum_internal.h ==== checkpolicy ==== Version update (3.8.1 -> 3.9) - Update to version 3.9 * Add support for wildcard netifcon names * Abort on mismatched declarations * Introduce neveraudit types ==== firewalld ==== Subpackages: firewalld-bash-completion firewalld-lang - Adding Python multiversion support, will enable firewalld pkg to provide Python libraries compatible with all supported Python versions. ==== hplip ==== Subpackages: hplip-hpijs hplip-sane hplip-udev-rules - Fix ReDoS issue in HPLIP's SLP parser (bsc#1245358) * add Fix-ReDoS-issue-in-HPLIP-s-SLP-parser.patch ==== libquicktime ==== - Enable faad2 support. ==== libselinux ==== Version update (3.8.1 -> 3.9) Subpackages: libselinux1 libselinux1-32bit selinux-tools - Update to version 3.9 * Fix local literal fcontext definitions priority * Fix order for path substitutions * Limit fcontext regex path length ==== libselinux-bindings ==== Version update (3.8.1 -> 3.9) - Update to version 3.9 * Fix local literal fcontext definitions priority * Fix order for path substitutions * Limit fcontext regex path length ==== libsemanage ==== Version update (3.8.1 -> 3.9) Subpackages: libsemanage-conf libsemanage2 - Update to version 3.9 * Improved POSIX compliance (added semanage_basename) * Add relabel_store config option * Add semanage_handle_create_with_path * Add relabel_store config option to semanage.conf ==== libsepol ==== Version update (3.8.1 -> 3.9) - Update to version 3.9 * Add new 'netif_wildcard' policy capability * Allow multiple policycap statements * Support genfs_seclabel_wildcard * Introduce neveraudit types ==== libzypp ==== Version update (17.37.12 -> 17.37.14) - During installation indicate the backend being used (bsc#1246038) If some package actually needs to know, it should test for ZYPP_CLASSIC_RPMTRANS being set in the environment. Otherwise the transaction is driven by librpm. - version 17.37.14 (35) - Workaround 'rpm -vv' leaving scriptlets /var/tmp (bsc#1218459) - Verbose log libproxy results if PX_DEBUG=1 is set. - BuildRequires: cmake >= 3.17. - version 17.37.13 (35) ==== lttng-ust ==== - Enable build for loongarch64 ==== ncompress ==== - Fix changelogs ==== openSUSE-build-key ==== - obsolete gpg-pubkey-ded64f3b, the openSUSE buildservice global key which was used mistakenly for repository signing. ==== patterns-xfce ==== Subpackages: patterns-xfce-xfce patterns-xfce-xfce_basis patterns-xfce-xfce_laptop - Use brignessctl for brigtness control on Xfce/Wayland Laptops code-o-o#leap/features#218 ==== policycoreutils ==== Version update (3.8.1 -> 3.9) Subpackages: policycoreutils-lang policycoreutils-python-utils python313-policycoreutils - Update to version 3.9 * setfiles: Add -U option to modify user and role portions * semodule: Add [-g PATH |--config=PATH] for an alternate path for the semanage config * Updated usr_etc.patch - Moved /etc/sestatus.conf to /usr/etc. - This patch is upstream: https://github.com/SELinuxProject/selinux/pull/415 ==== python-semanage ==== Version update (3.8.1 -> 3.9) - Update to version 3.9 * Improved POSIX compliance (added semanage_basename) * Add relabel_store config option * Add semanage_handle_create_with_path * Add relabel_store config option to semanage.conf ==== qemu ==== Subpackages: qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ipxe qemu-ksm qemu-lang qemu-microvm qemu-pr-helper qemu-seabios qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios qemu-vmsr-helper qemu-x86 - Fix bsc#1246566: * [roms] seabios: include "pciinit: don't misalign large BARs" (bsc#1246566) ==== xf86-video-voodoo ==== - add '--install' option to 'autoreconf --force' to fix build on TW