Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package bubblewrap for openSUSE:Factory checked in at 2026-09-08 16:53:10 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/bubblewrap (Old) and /work/SRC/openSUSE:Factory/.bubblewrap.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "bubblewrap" Tue Sep 8 16:53:10 2026 rev:25 rq:1376120 version:0.12.0 Changes: -------- --- /work/SRC/openSUSE:Factory/bubblewrap/bubblewrap.changes 2026-05-04 12:48:55.810148207 +0200 +++ /work/SRC/openSUSE:Factory/.bubblewrap.new.1265/bubblewrap.changes 2026-09-08 16:53:40.891868413 +0200 @@ -1,0 +2,24 @@ +Mon Aug 31 07:39:37 UTC 2026 - Kyle Scheuing <[email protected]> + +- update to 0.12.0: + * The flag --not-a-security-boundary was added. If this is enabled + then failure of some sandbox setup steps (like remounting a + submount) are not fatal. + * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1 + (or later). + * This version removes the support for building a setuid + bubblewrap. Changes in this version made it difficult to support + and basically all modern linux distributions now support + unprivileged user namespaces to some extent. + * The assume_kernel build option was added, if specified no backwards + compatiblity for kernels older than this is built in (and will result + in hard failures at runtime). Currently specifying 5.6.0 or + later will disable the fallback implementation of + openat2(RESOLVE_IN_ROOT). + * Bubblewrap now correctly resolves absolute symlinks during the + sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback + implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx) + where file or directories created during sandbox setup could + follow parent symlinks out of the sandbox. + +------------------------------------------------------------------- Old: ---- bubblewrap-0.11.2.tar.xz bubblewrap-0.11.2.tar.xz.sha256sum New: ---- bubblewrap-0.12.0.tar.xz bubblewrap-0.12.0.tar.xz.sha256sum ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ bubblewrap.spec ++++++ --- /var/tmp/diff_new_pack.D27hUV/_old 2026-09-08 16:53:41.568896817 +0200 +++ /var/tmp/diff_new_pack.D27hUV/_new 2026-09-08 16:53:41.570896901 +0200 @@ -18,10 +18,10 @@ Name: bubblewrap -Version: 0.11.2 +Version: 0.12.0 Release: 0 Summary: Core execution tool for unprivileged containers -License: LGPL-2.0-or-later +License: LGPL-2.1-or-later Group: Productivity/Security URL: https://github.com/containers/bubblewrap Source0: %{url}/releases/download/v%{version}/%{name}-%{version}.tar.xz ++++++ bubblewrap-0.11.2.tar.xz -> bubblewrap-0.12.0.tar.xz ++++++ ++++ 4493 lines of diff (skipped) ++++++ bubblewrap-0.11.2.tar.xz.sha256sum -> bubblewrap-0.12.0.tar.xz.sha256sum ++++++ --- /work/SRC/openSUSE:Factory/bubblewrap/bubblewrap-0.11.2.tar.xz.sha256sum 2026-05-04 12:48:55.802147877 +0200 +++ /work/SRC/openSUSE:Factory/.bubblewrap.new.1265/bubblewrap-0.12.0.tar.xz.sha256sum 2026-09-08 16:53:40.882868036 +0200 @@ -1 +1 @@ -69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 *bubblewrap-0.11.2.tar.xz +9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 *bubblewrap-0.12.0.tar.xz
