Packages changed: GraphicsMagick Mesa (26.2.1 -> 26.2.2) Mesa-drivers (26.2.1 -> 26.2.2) NetworkManager apache2-mod_php8 (8.5.9 -> 8.5.10) curl (8.21.0 -> 8.22.0) gdm (50.2 -> 50.3) google-noto-fonts (20260801 -> 20260901) gtk4 (4.22.4+29 -> 4.22.4+35) kernel-source (7.2.2 -> 7.2.3) libfastjson (1.2304.0+ga630254 -> 1.2609.0) libfido2 libreoffice (26.2.5.2 -> 26.8.0.3) mozjs140 (140.14.0 -> 140.15.0) openSUSE-release (20260904 -> 20260907) osinfo-db (20251212 -> 20260812) perl-Net-DNS (1.560.0 -> 1.570.0) php8 (8.5.9 -> 8.5.10) python-dnspython python-idna (3.18 -> 3.19) python-kiwi (10.3.9 -> 10.3.11) rsyslog (8.2606.0 -> 8.2608.0) salt strace virtualbox virtualbox-kmp (7.2.16_k7.2.0_1 -> 7.2.16_k7.2.3_1) === Details === ==== GraphicsMagick ==== Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2025-55154: integer overflow when performing magnified size calculations in ReadOneMNGIMage can lead to out-of-bounds write [bsc#1248078] * GraphicsMagick-CVE-2025-55154.patch ==== Mesa ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== Mesa-drivers ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-lang NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add NetworkManager-CVE-2026-10805.patch: dhclient: reject unsafe characters in URLs and hostnames (bsc#1267696, CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426). - Add NetworkManager-CVE-2026-19685.patch: core: 802.1x: reject ca-path for private connections (bsc#1276764, CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513). ==== apache2-mod_php8 ==== Version update (8.5.9 -> 8.5.10) - version update to 8.5.10 Core: Fixed bug GH-22782 (Const expr FCC crashes under preloading). Fixed bug GH-23088 (Stack overflow when comparing deeply nested arrays). Date: Fixed leak on double DatePeriod::__construct() call. DOM: Fixed bug GH-23116 (Stack overflow when normalizing a deeply nested DOMDocument). Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested Dom\XMLDocument). Fixed bug GH-22825 (DOMElement::setAttribute() fails silently when the DTD declares a default value for the attribute). Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes with DOMNode::isEqualNode()). Exif: Fixed exif_read_data() allocating a HEIF meta box larger than the file it came from. Intl: Fixed IntlListFormatter::__construct() leaving stale global error state after successful calls. Opcache: Fixed GH-22693 (DT_TEXTREL in JIT-generated TLS access on x86_64). Fixed bug GH-22763 (JIT fails to clear ZREG_TYPE_ONLY after setting reg). Fixed bug GH-22857 (Function JIT emits wrong code for FETCH_OBJ_FUNC_ARG on a property hook getter, losing register-held variables). Fixed bug GH-22916 (Preserve parent regs in zend_jit_deoptimizer_start()). OpenSSL: Fix missing error check on invalid alpn protocols. MBString: Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative offset in a non-UTF-8 encoding). Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi() invalidates the regex cache). PCRE: Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is now forbidden. PDO_ODBC: Fixed bug GH-23016 (NULL values in long columns come back as garbage binary strings). PDO_PGSQL: Fixed several lazy fetch (PDO::ATTR_PREFETCH => 0) defects: an infinite loop when cleaning up a fetch left in a COPY, a use-after-free when a statement with emulated or disabled prepares is destroyed, a connection left busy for the next fetch, and rows delivered from a result another statement took over. Reflection: Fixed bug GH-22905 (Reflection exception messages truncate on null bytes). Fixed ReflectionProperty::isLazy() and skipLazyInitialization() using the parent slot when a child class hooks an inherited property. Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. Session: Fix corruption in mod_mm. Fixed bug GH-23043 (broken session id code can cause zend_mm_heap corrupted). SimpleXML: Fixed integer element offsets that cannot resolve aliasing an existing element. Fixed segfault when comparing uninitialized SimpleXMLElement instances. Sockets: Fixed socket_set_option() validation error messages for UDP_SEGMENT and SO_LINGER options. Fixed various memory related issues in ext/sockets. SQLite: Fix leak when trying to close db if blob stream is still open. Standard: Fixed bug GH-23111 (Stack overflow in array_walk_recursive() with deeply nested arrays). Fixed bug GH-23113 (Stack overflow in array_replace_recursive() with deeply nested arrays). Fixed bug GH-23115 (Stack overflow in compact() with deeply nested arrays). Streams: Fixed bug GH-15836 (Use-after-free when a user stream filter accesses $this->stream during the close flush). XSL: Fixed use-after-free when a DOMDocument subclass __clone() retains the stylesheet copy made by XSLTProcessor::importStylesheet(). - Removed php-fix-build-gcc16.patch (fixed upstream) ==== curl ==== Version update (8.21.0 -> 8.22.0) Subpackages: curl-zsh-completion libcurl4 - Update to 8.22.0: * Security fixes: - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476) - CVE-2026-18924: HTTP/2 server push UAF (bsc#1277477) - CVE-2026-19931: Negotiate ambient user conn reuse (bsc#1277478) - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479) - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480) - CVE-2026-80255: secure cookie attribute bypass with tab (bsc#1277482) - CVE-2026-82209: curl: domain-scoped PSL domain cookie (bsc#1278173) * Changes: - gssapi: add support for Apple GSS Framework - hardening: add API guards - RFC 9421 HTTP Message Signatures support - spnego: block NTLM fallback in SPNEGO negotiation - TLS: drop support for TLS-SRP - vquic: add option to use Apple fast UDP * Bugfixes: - altsvc: continue after unknown parameters - asyn-thrdd: retry link-local ipv6 if missing scope id - autotools: minor fixes and improvements - cd2nroff: fix backslashes for 4-space indent lines - cd2nroff: stricter checks for asterisks for italics - cfilters: fix event-based connection shutdown - conncache: apply multi limits to transfers using a shared pool - connect: only set connect timer on first socket - connection reuse: check SSL configs when doing a scheme upgrade - cookie: cookies set for an exact PSL domain is host-only - cookie: improve TAB handling - cookie: refuse to load cookies set against a PSL domain - FTP: fix TLS session reuse on the data connection - hostip: only cache negative resolves for authoritative answers - http digest: tie peer/credentials on input - http2: make server push transfers inherit share from parent - ldap: reject control characters in URL-decoded filter values - ldap: support empty username and password - md5: replace magic numbers with `MD5_DIGEST_LEN` - mime.c: avoid integer overflow in base64 size calculation - mprintf: acknowledge %F - ngtcp2+openssL: fix early data - ngtcp2: avoid NULL deref in cf_ngtcp2_send - openssl+sectrust: fix session reuse - openssl+sectrust: move session verified set into result check - openssl: avoid conn reuse if provider is used - openssl: avoid strlen() on the data from OpenSSL - openssl: prefer modern API flavors for `EVP_MD_CTX` new/free - openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` - url: fix handling of empty user in NTLM matching - url: fix negotiate/ntlm connection reuse - urlapi: allow URLs to not have userauth (hostname) - urlapi: clear password buffer on error path - vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config * Rebase libcurl-ocloexec.patch ==== gdm ==== Version update (50.2 -> 50.3) Subpackages: gdm-lang gdm-schema gdm-systemd gdm-xdm-integration libgdm1 typelib-1_0-Gdm-1_0 - Update to version 50.3: + Fixed pam_gdm regression where a previous security fix caused authentication to fail on systemd, which intentionally leaves the kernel keyring buffer unterminated + Fixed potential use-after-free where gdm-session-settings did not keep a reference to the user, which could be freed by the manager while it was still emitting signals + Fixed connection reference leaks and a use-after-free crash in session worker connection teardown that could bring down the whole user session during screen lock/unlock + Updated translations. ==== google-noto-fonts ==== Version update (20260801 -> 20260901) Subpackages: google-noto-sans-arabic-fonts google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20260901: * Serif Toto: - Improve the Kerning of BREATHY EO - Reverts the change to the dot under TOTO LETTER WA * Sans Miao: Add 9 Miao glyph variants for the Lipo language ==== gtk4 ==== Version update (4.22.4+29 -> 4.22.4+35) Subpackages: gtk4-lang gtk4-schema gtk4-tools libgtk-4-1 typelib-1_0-Gtk-4_0 - Update to version 4.22.4+35: + css: Fix invalidation for text decorations + gtkapplication-wayland: Add a missing NULL check when forgetting a window + Updated translations. ==== kernel-source ==== Version update (7.2.2 -> 7.2.3) - Update patches.kernel.org/7.2.1-083-ptp-vmclock-prevent-read-only-mappings-from-bec.patch (bsc#1012628 CVE-2026-80724 bsc#1277850). - Update patches.kernel.org/7.2.2-001-inet-frags-strip-GSO-state-from-fragments-befor.patch (bsc#1012628 CVE-2026-80590 bsc#1277275). suse-add-cves - commit 263d925 - Update config files. - commit a590eb7 - Update config files. - commit f305596 - Linux 7.2.3 (bsc#1012628). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (bsc#1012628). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (bsc#1012628). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (bsc#1012628). - USB: serial: spcp8x5: drop broken carrier detect support (bsc#1012628). - USB: serial: option: fix slab OOB read in interrupt URB callback (bsc#1012628). - ALSA: usb-audio: Complete cleanup after system-resume errors (bsc#1012628). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (bsc#1012628). - ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB (bsc#1012628). - usb: core: Strengthen error handling in hub_hub_status() (bsc#1012628). - usb: core: Add lock to usb_wakeup_notification() (bsc#1012628). - KVM: s390: vsie: zero stale crypto bits (bsc#1012628). - crypto: qce - Remove unsafe/deprecated algorithms (bsc#1012628). - crypto: mxs-dcp - fix source scatterlist length access (bsc#1012628). - crypto: iaa - fall back to software for multi-entry scatterlists (bsc#1012628). - crypto: qce - fix CCM AAD buffer underallocation (bsc#1012628). - crypto: krb5 - use kfree_sensitive() for derived key buffers (bsc#1012628). - crypto: atmel-tdes - use scatterlist length before DMA mapping (bsc#1012628). - crypto: sun8i-ss - Remove crypto_rng interface (bsc#1012628). - crypto: sun8i-ce - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Allow zero as a random number (bsc#1012628). - crypto: qcom-rng - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Enable clock in hwrng case (bsc#1012628). - crypto: virtio - bound the akcipher result length (bsc#1012628). - kunit: irq: Continue increasing hrtimer interval for longer (bsc#1012628). - mm/swap: reject swapon() on filesystem-level encrypted files (bsc#1012628). - netfilter: nf_tables: don't queue packet path object notifications (bsc#1012628). - netfilter: nft_set_pipapo_avx2: add missing vzeroupper (bsc#1012628). - vxlan: keep the last remote linked during FDB flush (bsc#1012628). - batman-adv: reject unrepresentable multicast TVLV offsets (bsc#1012628). - ipv6: seg6: clear IPv4 control block on IPIP decapsulation (bsc#1012628). - net/packet: defer vmalloc TX_RING free until skbs finish (bsc#1012628). - vlan: fix skb_under_panic and races when toggling HW VLAN offload (bsc#1012628). - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (bsc#1012628). - xfrm: bound nat keepalive state collection (bsc#1012628). - xfrm: fix xfrm_state_construct() auth-trunc leak (bsc#1012628). - xfrm: ah6: validate routing header segments_left (bsc#1012628). - xfrm: avoid lock inversion in nat keepalive work (bsc#1012628). - xfrm: drop ESP-in-TCP packets with no ingress device (bsc#1012628). - tcp: clamp route advmss to TCP_MIN_MSS (bsc#1012628). - xfrm: espintcp: fix UAF during close (bsc#1012628). - net: advertise TCP MSS from the configured MTU, not the learned PMTU (bsc#1012628). - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer (bsc#1012628). - tcp: fix AO info use-after-free in tcp_ao_connect_init() (bsc#1012628). - net/tcp: fix TCP-AO key deletion in VRFs (bsc#1012628). - gtp: serialize PDP context updates (bsc#1012628). - tls: device: fix out-of-bounds write in tls_append_frag() (bsc#1012628). - KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y (bsc#1012628). - KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable (bsc#1012628). - KVM: SEV: Extract loading of guest-provided VMSA to a separate helper (bsc#1012628). - KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests (bsc#1012628). - KVM: SEV: Drop FOLL_WRITE for encrypted region registration (bsc#1012628). - KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts (bsc#1012628). ... changelog too long, skipping 49 lines ... - commit dcfc956 ==== libfastjson ==== Version update (1.2304.0+ga630254 -> 1.2609.0) - Update to 1.2609.0: * Speed up object member lookup by traversing child pages directly * Fix buffered JSON dumping with zero-sized and small caller- provided workspaces * Ensure correct linking with libm on glibc 2.42 and later * Correct transposed calloc() arguments that trigger warnings with newer compilers * Clarify string-buffer lifetime and thread-safety guarantees in the API documentation * Expand correctness tests, fuzzing, and cross-platform CI coverage ==== libfido2 ==== Subpackages: libfido2-1 libfido2-udev - Drop USE_HIDAPI, as it produces a race condition (bsc#1234010) ==== libreoffice ==== Version update (26.2.5.2 -> 26.8.0.3) Subpackages: libreoffice-base libreoffice-calc libreoffice-draw libreoffice-filters-optional libreoffice-gnome libreoffice-gtk3 libreoffice-icon-themes libreoffice-impress libreoffice-l10n-cs libreoffice-l10n-da libreoffice-l10n-de libreoffice-l10n-el libreoffice-l10n-en libreoffice-l10n-en_GB libreoffice-l10n-es libreoffice-l10n-fr libreoffice-l10n-hu libreoffice-l10n-it libreoffice-l10n-ja libreoffice-l10n-pl libreoffice-l10n-pt_BR libreoffice-l10n-ru libreoffice-l10n-zh_CN libreoffice-l10n-zh_TW libreoffice-mailmerge libreoffice-math libreoffice-pyuno libreoffice-qt6 libreoffice-writer libreofficekit - Update to 26.8.0.3: * Release notes: https://wiki.documentfoundation.org/Releases/26.8.0/RC3 - Update bundled pdfium to 7681 and skia to m147 as required by the new download.lst. - Add box2d-detection.patch: configure derived the box2d version from pkg-config only, which fails with the box2d 2.4.1 we ship as it installs no box2d.pc. - Drop Qt 5 support in SLFO and Tumbleweed (related: boo#1277445) ==== mozjs140 ==== Version update (140.14.0 -> 140.15.0) - Update to version 140.15.0: + See https://www.firefox.com/en-US/firefox/140.15.0/releasenotes/ ==== openSUSE-release ==== Version update (20260904 -> 20260907) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== osinfo-db ==== Version update (20251212 -> 20260812) - Update to database version 20260812 (jsc#PED-14625) osinfo-db-20251212.tar.xz - Drop patches contained in new tarball Add-optional-recommended-attribute-to-firmware.patch add-win-2k19-media-info.patch add-sles16-support.patch (see bsc#1268781) - Update add-sles16.1-support.patch ==== perl-Net-DNS ==== Version update (1.560.0 -> 1.570.0) - updated to 1.570.0 (1.57) see /usr/share/doc/packages/perl-Net-DNS/Changes Resync with IANA DNS parameters registry. EDNS: Add support for MQTYPE-QUERY option. Fix rt.cpan.org #181125 Unbounded recursion when re-encoding message with misplaced TSIG CVE-2026-81928 bsc#1278084 Fix rt.cpan.org #180773 UNIX resolver can fail in taint mode ==== php8 ==== Version update (8.5.9 -> 8.5.10) Subpackages: php8-ctype php8-dom php8-iconv php8-openssl php8-pdo php8-sqlite php8-tokenizer php8-xmlreader php8-xmlwriter - version update to 8.5.10 Core: Fixed bug GH-22782 (Const expr FCC crashes under preloading). Fixed bug GH-23088 (Stack overflow when comparing deeply nested arrays). Date: Fixed leak on double DatePeriod::__construct() call. DOM: Fixed bug GH-23116 (Stack overflow when normalizing a deeply nested DOMDocument). Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested Dom\XMLDocument). Fixed bug GH-22825 (DOMElement::setAttribute() fails silently when the DTD declares a default value for the attribute). Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes with DOMNode::isEqualNode()). Exif: Fixed exif_read_data() allocating a HEIF meta box larger than the file it came from. Intl: Fixed IntlListFormatter::__construct() leaving stale global error state after successful calls. Opcache: Fixed GH-22693 (DT_TEXTREL in JIT-generated TLS access on x86_64). Fixed bug GH-22763 (JIT fails to clear ZREG_TYPE_ONLY after setting reg). Fixed bug GH-22857 (Function JIT emits wrong code for FETCH_OBJ_FUNC_ARG on a property hook getter, losing register-held variables). Fixed bug GH-22916 (Preserve parent regs in zend_jit_deoptimizer_start()). OpenSSL: Fix missing error check on invalid alpn protocols. MBString: Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative offset in a non-UTF-8 encoding). Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi() invalidates the regex cache). PCRE: Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is now forbidden. PDO_ODBC: Fixed bug GH-23016 (NULL values in long columns come back as garbage binary strings). PDO_PGSQL: Fixed several lazy fetch (PDO::ATTR_PREFETCH => 0) defects: an infinite loop when cleaning up a fetch left in a COPY, a use-after-free when a statement with emulated or disabled prepares is destroyed, a connection left busy for the next fetch, and rows delivered from a result another statement took over. Reflection: Fixed bug GH-22905 (Reflection exception messages truncate on null bytes). Fixed ReflectionProperty::isLazy() and skipLazyInitialization() using the parent slot when a child class hooks an inherited property. Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. Session: Fix corruption in mod_mm. Fixed bug GH-23043 (broken session id code can cause zend_mm_heap corrupted). SimpleXML: Fixed integer element offsets that cannot resolve aliasing an existing element. Fixed segfault when comparing uninitialized SimpleXMLElement instances. Sockets: Fixed socket_set_option() validation error messages for UDP_SEGMENT and SO_LINGER options. Fixed various memory related issues in ext/sockets. SQLite: Fix leak when trying to close db if blob stream is still open. Standard: Fixed bug GH-23111 (Stack overflow in array_walk_recursive() with deeply nested arrays). Fixed bug GH-23113 (Stack overflow in array_replace_recursive() with deeply nested arrays). Fixed bug GH-23115 (Stack overflow in compact() with deeply nested arrays). Streams: Fixed bug GH-15836 (Use-after-free when a user stream filter accesses $this->stream during the close flush). XSL: Fixed use-after-free when a DOMDocument subclass __clone() retains the stylesheet copy made by XSLTProcessor::importStylesheet(). - Removed php-fix-build-gcc16.patch (fixed upstream) ==== python-dnspython ==== - Skip tests failing with idna 1.19 ==== python-idna ==== Version update (3.18 -> 3.19) - update to 3.19: * Restore the `std3_rules` option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that `uts46_remap()` defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again. * Performance improvements to UTS #46 mapping, particularly for ASCII-only domains. * Test on free-threaded CPython with the GIL disabled and document thread safety. * Expose the Unicode version of the generated tables as `idna.unicode_version`, and show it in `idna --version`. * Add `code`, `text`, `codepoint` and `position` attributes to `IDNAError` so that the failed rule and the offending character can be identified without parsing the exception message. * The deprecated `transitional` argument to `encode()` and `uts46_remap()` is now completely ignored, and gives a deprecation warning for the latter. * Reject A-labels that are not the canonical Punycode encoding of their U-label. * Fix CONTEXTJ violations raising `IDNAError` instead of `InvalidCodepointContext`. * Consistently raise `IDNAError` for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec. * Add property-based tests, extended fuzzing targets, coverage * measurement, and CI checks that the data tables match the generator output. * Various code quality and tooling improvements. ==== python-kiwi ==== Version update (10.3.9 -> 10.3.11) - Bump version: 10.3.10 → 10.3.11 - Fix system mount list for chroot operations Add /sys/fs/cgroup to the bind mount list as it is not transported into the chroot when bind mounting only /sys. This fixes problems for applications that runs as part of image scripts or package scripts and required access to the cgroups interface. - Update LVM integration test Add a profile for building a DOS only LVM image and one with GPT - Fix setup of partition IDs When setting the partition type code (gUID, UUID) the partition id hex code gets resetted to Linux(83) when it should stay at the value it had before. This causes for example on LVM type(8e) partitions a reset to Linux(83) which is unwanted. With this commit we make sure the partition type hex code gets reset to the correct value. This Fixes #3036 - Bump version: 10.3.9 → 10.3.10 - doc: contributing: Rework AI policy This is more in line with our intent and legal frameworks we operate in. - Add SparseFile utility class Add SparseFile class to consolidate sparse file creation to be performed by either qemu-img or dd and replace all direct qemu-img create calls by SparseFile.create(...). This Fixes #3027 Assisted-by: GPT-5.3 - add autouse fixture that prevents /etc/kiwi.yml from loading Currently kiwi will by default load the runtime config files, but that has the disadvantage that the users config leaks into the test environment and breaks certain tests that assume that the default tool is `foo`, but the users settings say `bar` - use f-strings - remove obsolete python version check - Fix test_baseVagrantSetup The test checks for settings to appear in lowercase, but depending on the OS this varies. This commit turns check string and output string to lowercase to allow a match in any case the setting occurs - Align docs with code (#3029) Align documentation with sources This is a giant collection of various fixes to the documentation that drifted from the source code. This is mostly new elements, removal of deprecated elements, new values, flags or changed behavior Co-authored-by: Claude Opus 5 Co-authored-by: GPT-5.6 Sol Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Marcus Schäfer - Fix test-image-aws-isolated-compute Explicitly request python3-base. Due to changes on the SUSE python packaging it's required to request python3-base such that symlinks like /usr/bin/python3 exists - Fix test-image-nitro-enclave rahide build test /etc/modules-load.d only exists if a kernel gets installed. For the container build to be used as input for nitro-cli this is not the case - Fix OVA compose to respect machine section configuration - Refactor OvaComposeTemplate for feature parity with VmwareSettingsTemplate - Extract disk controller, network driver from machine section - Support multiple NICs with per-interface configuration - Add virtual hardware version (vmx-${version}) support Fixes: #3025 Co-authored-by: copilot - Fixed build status helper Make sure to show disabled build tests correctly ==== rsyslog ==== Version update (8.2606.0 -> 8.2608.0) - upgrade to rsyslog 8.2608.0 - dropped patches: * 0001-imptcp-guard-regex-framing-match-at-line-start.patch * 2026-08-18: imbeats: rearm listener after failed TLS accept * 2026-08-18: msg: serialize turbo snapshot duplication * 2026-08-18: omfile: harden dynafile default containment * 2026-08-18: fixup! omfwd: support PKCS#11 URIs with ossl TLS * 2026-07-02: omfwd: support PKCS#11 URIs with ossl TLS * 2026-07-21: mmkubernetes: reload SA token proactively and on HTTP 401 * 2026-08-17: devtools: remove Cubic from local validation * 2026-08-14: mmnormalize: share turbo $! snapshot across MsgDup by refcount * 2026-08-11: tcpsrv: synchronize session table slots * 2026-08-11: imrelp: preserve errno across stop signal * 2026-08-12: examples.rst: Missing space in template * 2026-08-10: mmnormalize: merge debug metadata * 2026-08-08: normalizers: complete debug test gating * 2026-08-08: normalizers: complete debug integration * 2026-08-07: mmnormalize, pmnormalize: add liblognorm debugging * 2026-08-07: msg: ignore null values in msgSetPropViaJSON() instead of crashing * 2026-08-07: runtime: make error-message flag atomic * 2026-07-24: fuzz: exercise RFC 3164 and RFC 5424 parsers * 2026-08-05: build: unify indentation in AC_CONFIG_FILES list * 2026-07-25: imfile: fix delay.message microsecond conversion * 2026-07-24: diskqueue: reject symlinked persisted segments * 2026-06-23: omfile: control symlink following * 2026-07-25: mmnormalize: make HUP reload worker-safe * 2026-07-24: docs(agents): add Cursor Cloud environment setup notes * 2026-07-22: imbeats: harden Lumberjack input resource handling * 2026-07-23: stringbuf: harden empty string replacement * 2026-07-20: imptcp: guard regex framing match at line start (bsc#1271910) * 2026-07-21: rainerscript: free cnfstmtNewAct nvlst once, at the done: label * 2026-07-21: queue: preserve DA child work during shutdown * 2026-07-21: imtcp: release completed zlib decoder state * 2026-07-09: doc: clarify JSON array rendering * 2026-07-21: Potential fixes for 5 code quality findings (#7397) * 2026-07-20: ratelimit: optimize port-based per-source keys * 2026-07-20: imtcp: make zstd window budget configurable * 2026-07-19: imtcp: use snake case for zstd window tracking * 2026-07-17: imtcp: bound aggregate zstd decoder window memory * 2026-07-20: statsobj: guard Prometheus escape writes * 2026-07-18: config: do not instantiate actions disabled via config.enabled="off" * 2026-07-15: queue: document DA engine internals * 2026-07-14: msg: enforce source-property helper contract * 2026-07-10: ratelimit: remove per-source key policy hot lock * 2026-07-08: ratelimit: speed source-key shortcuts * 2026-07-15: queue: clarify DA transfer worker role * 2026-07-18: compat_queue: add missing STAILQ_FOREACH/STAILQ_NEXT fallback * 2026-07-18: rainerscript: warn on constant AND/OR operand at parse time * 2026-07-18: configure: include in the STAILQ detection test * 2026-07-17: mmnormalize: share Turbo CEE root path check * 2026-07-17: mmnormalize: fall back after Turbo materialization failure * 2026-07-17: mmnormalize: preserve turbo results across message boundaries * 2026-07-17: benchmarks: harden comparison and helper inputs * 2026-07-16: segdisk: optimize CRC accounting and add benchmarks * 2026-07-15: imjournal: stop invalidation reopen busy-loop * 2026-07-14: queue: harden segmented DA lifecycle invariants * 2026-07-14: queue: harden DA portability and startup cleanup * 2026-07-14: queue: address segmented DA review findings * 2026-07-14: queue: stabilize DA shutdown and reload state * 2026-07-14: queue: clarify lazy marker and legacy state paths * 2026-07-14: queue: gate idle cleanup on durable intent * 2026-07-14: queue: document empty DA marker replacement * 2026-07-14: queue: preserve classic state on transient load errors * 2026-07-14: queue: make idle cleanup restoration crash safe * 2026-07-14: queue: fail classic DA startup on real errors * 2026-07-14: queue: clarify dirty DA configuration handling * 2026-07-14: queue: separate DA idle and worker timeouts * 2026-07-14: queue: document DA auto-upgrade boundary * 2026-07-14: queue: publish fresh DA markers on first spill * 2026-07-14: queue: constrain classic DA startup fallback * 2026-07-14: queue: clarify disabled DA idle timeout * 2026-07-14: queue: preserve classic DA startup fallback * 2026-07-14: doc: describe segmented disk-assisted queues * 2026-07-14: queue: add segmented disk-assisted engine * 2026-07-14: queue: retain adopted recovery frontier * 2026-07-14: queue: address segmented disk review findings * 2026-07-13: queue: wake workers before capacity waits * 2026-07-13: queue: make segmented deletion resumable * 2026-07-13: queue: initialize missing state in empty spool dirs * 2026-07-13: queue: reject invalid segmented codec field types * 2026-07-13: queue: avoid sanitized generation wrap * 2026-07-13: queue: expose segmented disk durability test hooks * 2026-07-13: queue: make segmented disk recovery lazy * 2026-07-09: queue: rework experimental segmented disk backend * 2026-07-08: imjournal: warn when failing to get the MESSAGE field * 2026-07-08: omawslogshlc: add CloudWatch Logs HLC output module * 2026-07-08: core: add systemd READY delay opt-in * 2026-06-02: core/imfile: synchronize sd_notify READY=1 with module startup * 2026-07-07: ratelimit: shard per-source state * 2026-07-06: docs: validate marked config samples * 2026-07-07: ratelimit: shard named config registry * 2026-07-06: runtime: harden ratelimit per-source reload * 2026-07-06: queue: align legacy action batch default * 2026-07-06: runtime: relax worker-count log reads * 2026-07-06: core: relax selected atomic flag reads * 2026-07-06: omkafka: relax poll stop flag atomics * 2026-07-06: doc: add documentation for imfile delay.message parameter * 2026-06-04: core: add generic output rate limiting * 2026-07-05: omelasticsearch: apply TLS options during detection ... changelog too long, skipping 63 lines ... * 2026-06-08: diag.sh: fix content-pattern-check and assert-first-column-sum-greater-than ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Fix "mount.swap" activation on UUID and add "resolve_canonical" arg - Added: * fix-mount.swap-activation-when-using-uuid-and-introd.patch ==== strace ==== - Remove unused sysvinit-tools and time - Don't require mpers support ==== virtualbox ==== - add Leap-16.1.patch (bsc#1274769) - add kernel-7.3.patch to fix build against kernel 7.3. ==== virtualbox-kmp ==== Version update (7.2.16_k7.2.0_1 -> 7.2.16_k7.2.3_1) - add Leap-16.1.patch (bsc#1274769) - add kernel-7.3.patch to fix build against kernel 7.3.