Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package s390-tools for openSUSE:Factory 
checked in at 2026-09-22 15:53:14
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/s390-tools (Old)
 and      /work/SRC/openSUSE:Factory/.s390-tools.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "s390-tools"

Tue Sep 22 15:53:14 2026 rev:124 rq:1379627 version:2.44.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/s390-tools/s390-tools.changes    2026-08-18 
16:38:54.345132375 +0200
+++ /work/SRC/openSUSE:Factory/.s390-tools.new.383539/s390-tools.changes        
2026-09-22 15:54:50.229245427 +0200
@@ -1,0 +2,68 @@
+Tue Sep 22 07:36:27 UTC 2026 - Nikolay Gueorguiev <[email protected]>
+
+- Upgrade s390-tools to version 2.44.1 
+  ( bsc#1273204, bsc#1273205, bsc#1273206, bsc#1273207, bsc#1275476 )
+  For Linux kernel version: 7.2
+  * Changes of existing tools:
+    - cpumf/lshwc: Add -c as short option for --counters
+    - cpumf/lspai: Handle CPU hotplug gracefully
+    - dbginfo.sh: Change grep for OS name
+    - dbginfo.sh: Change tar generation via temp file
+    - dbginfo.sh: Correct dump counter
+    - dbginfo.sh: Detect the openCryptoki STDLL directory at runtime
+    - dbginfo.sh: Redirect stderr on command existence checks
+    - dbginfo.sh: Replace deprecated backtick command substitution
+    - dbginfo.sh: Secure the directory input variable
+    - zipl: Detect and display partition table type for disk and device
+  * Bug Fixes:
+    - cmsfs-fuse: Fix out-of-bounds access when reading variable-length files
+    - cpumf/lscpumf: Fix exit status and error reporting
+    - cpumf/lshwc: Fix --allcpu to --all in man page
+    - cpumf/lspai: Add input validation for interval parameter
+    - cpumf/lspai: Fix --allcpu to --all in man page
+    - cpumf/lspai: Fix integer overflow in file descriptor calculation
+    - cpumf/lspai: Fix output formatting with minimum indent
+    - dasdview: Fix buffer overflow in dasdview_read_vtoc()
+    - dumpconf: Harden locking during delayed activation to prevent symlink 
attacks
+    - fdasd: Fix potential buffer overflow in fdasd_change_part_type()
+    - ipl_tools: Fix buffer overflow vulnerabilities in chreipl and is_lpar()
+    - ip_watcher: Use mktemp for cleanup files to avoid collisions
+    - libkmipclient: Fix NULL pointer dereference in 
kmip_v2_attr_from_v1_attr()
+    - libkmipclient: Fix heap buffer overflow
+    - libutil/util_lockfile: Prevent buffer overflow in lockfile handling
+    - libzds: Add bounds checking and validate used_bytes in PDS directory 
parsing
+    - pvattest: Write attestation request private key (arpk) with 0600 
permissions
+    - pvebc: Fix executable permission on sel-ebc-modules.conf
+    - pvics: Fix incorrect exit values for --version and --help options
+    - pvsecret: Write secret with 0600 permissions
+    - sclpdbf: Harden against invalid trace data
+    - vmur: Fix buffer over-read in get_minor()
+    - zdump/dfi_s390: Add a check for zlib entry size in the dump header
+    - zdump/dfi_s390: Fix out-of-bounds upon dump entry decompression
+    - zdump/dfo_elf: Fix 32-bit truncation in ELF header allocation size
+    - zdump: Reject multi-volume dumps with out-of-range vol_cnt
+    - ziomon/ziomon_zfcpdd: Validate message lengths before processing
+    - ziomon/ziorep_config: Replace unsafe open() and regex match with safer 
idioms
+    - ziomon: Validate message layout and aggregate message lengths before 
processing
+    - zipl: Fix memory leak in free_bootloader()
+    - zipl: Replace popen(3) with safer invocation for targetbase scripts and 
ngdump
+    - zkey-ekmfweb: Fix insecure default: TLS host name verification now 
enabled by default
+    - zkey-kmip: Fix insecure default: TLS host name verification now enabled 
by default
+    - zkey: Fix memory leaks when generating keys or reenciphering integrity 
volumes
+    - zkey: Harden 'zkey kms unbind' command against symlink traversal
+    - zkey: Harden KMS config directory handling against symlink attacks
+    - zkey: Harden KMS plugin file handling against symlink attacks
+    - zkey: Install initrd integration with the configured plugin directory
+  * Full Changelog: v2.44.0...v2.44.1 
+      [https://github.com/ibm-s390-linux/s390-tools/compare/v2.44.0...v2.44.1]
+- Removed obsolete patches for Security vulnerabilities for zkey and friends
+  * s390-tools-zkey-Harden-KMS-config-directory-handling.patch
+    - zkey: Harden KMS config directory handling - Commit `0eef784`
+  * s390-tools-zkey-Harden-zkey-kms-unbind-command.patch
+    - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15`
+  * s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch
+    - zkey/ekmfweb, zkey/kmip: Harden KMS plugin file handling - Commit 
`bc81c32`
+- Reworked s390-tools-Remove-phmac_s390.patch
+- Re-vendor-ed vendor.tar.zst
+
+-------------------------------------------------------------------

Old:
----
  s390-tools-2.44.0.tar.gz
  s390-tools-zkey-Harden-KMS-config-directory-handling.patch
  s390-tools-zkey-Harden-zkey-kms-unbind-command.patch
  s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch

New:
----
  s390-tools-2.44.1.tar.gz

----------(Old B)----------
  Old:- Removed obsolete patches for Security vulnerabilities for zkey and 
friends
  * s390-tools-zkey-Harden-KMS-config-directory-handling.patch
    - zkey: Harden KMS config directory handling - Commit `0eef784`
  Old:    - zkey: Harden KMS config directory handling - Commit `0eef784`
  * s390-tools-zkey-Harden-zkey-kms-unbind-command.patch
    - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15`
  Old:    - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15`
  * s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch
    - zkey/ekmfweb, zkey/kmip: Harden KMS plugin file handling - Commit 
`bc81c32`
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ s390-tools.spec ++++++
--- /var/tmp/diff_new_pack.E72Wlg/_old  2026-09-22 15:54:51.685305412 +0200
+++ /var/tmp/diff_new_pack.E72Wlg/_new  2026-09-22 15:54:51.687305494 +0200
@@ -24,7 +24,7 @@
 %endif
 
 Name:           s390-tools
-Version:        2.44.0
+Version:        2.44.1
 Release:        0
 Summary:        S/390 tools like zipl and dasdfmt for s390x (plus selected 
tools for x86_64)
 License:        MIT
@@ -92,9 +92,6 @@
 
 ###
 # IBM patches
-Patch101:       s390-tools-zkey-Harden-KMS-config-directory-handling.patch
-Patch102:       s390-tools-zkey-Harden-zkey-kms-unbind-command.patch
-Patch103:       
s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch
 ###
 # SUSE patches
 Patch900:       s390-tools-combined.patch

++++++ s390-tools-2.44.0.tar.gz -> s390-tools-2.44.1.tar.gz ++++++
++++ 7234 lines of diff (skipped)

++++++ s390-tools-Remove-phmac_s390.patch ++++++
--- /var/tmp/diff_new_pack.E72Wlg/_old  2026-09-22 15:54:52.692346899 +0200
+++ /var/tmp/diff_new_pack.E72Wlg/_new  2026-09-22 15:54:52.695347022 +0200
@@ -1,14 +1,14 @@
 diff -Naur a/etc/modules-load.d/s390-pkey.conf 
b/etc/modules-load.d/s390-pkey.conf
---- a/etc/modules-load.d/s390-pkey.conf        2026-02-16 15:33:48.000000000 
+0100
-+++ b/etc/modules-load.d/s390-pkey.conf        2026-04-17 09:32:27.895965780 
+0200
+--- a/etc/modules-load.d/s390-pkey.conf        2026-09-21 19:36:47.000000000 
+0200
++++ b/etc/modules-load.d/s390-pkey.conf        2026-09-22 10:04:20.104771268 
+0200
 @@ -4,4 +4,3 @@
  pkey_ep11
  pkey_cca
  paes_s390
 -phmac_s390
-diff -Naur a/zkey/dracut/99-pkey.conf b/zkey/dracut/99-pkey.conf
---- a/zkey/dracut/99-pkey.conf 2026-02-16 15:33:48.000000000 +0100
-+++ b/zkey/dracut/99-pkey.conf 2026-04-17 09:34:04.888735927 +0200
+diff -Naur a/zkey/dracut/99-pkey.conf.in b/zkey/dracut/99-pkey.conf.in
+--- a/zkey/dracut/99-pkey.conf.in      2026-09-21 19:36:47.000000000 +0200
++++ b/zkey/dracut/99-pkey.conf.in      2026-09-22 10:02:17.647392941 +0200
 @@ -4,6 +4,6 @@
  # it under the terms of the MIT license. See LICENSE for details.
  #
@@ -16,10 +16,10 @@
 -add_drivers+=" uvdevice pkey pkey_cca pkey_ep11 pkey_pckmo pkey_uv paes_s390 
phmac_s390 zcrypt zcrypt_cex4 "
 +add_drivers+=" uvdevice pkey pkey_cca pkey_ep11 pkey_pckmo pkey_uv paes_s390 
zcrypt zcrypt_cex4 "
  install_items+=" chzcrypt lszcrypt zkey zkey-cryptsetup "
- install_optional_items+=" /usr/lib64/zkey/*.so  /etc/zkey/* 
/etc/zkey/repository/* /etc/zkey/kmip/profiles/* "
-diff -Naur a/zkey/initramfs/hooks/s390-tools-zkey 
b/zkey/initramfs/hooks/s390-tools-zkey
---- a/zkey/initramfs/hooks/s390-tools-zkey     2026-02-16 15:33:48.000000000 
+0100
-+++ b/zkey/initramfs/hooks/s390-tools-zkey     2026-04-17 09:34:41.161023939 
+0200
+ install_optional_items+=" %ZKEYKMSPLUGINDIR%/*.so  /etc/zkey/* 
/etc/zkey/repository/* /etc/zkey/kmip/profiles/* "
+diff -Naur a/zkey/initramfs/hooks/s390-tools-zkey.in 
b/zkey/initramfs/hooks/s390-tools-zkey.in
+--- a/zkey/initramfs/hooks/s390-tools-zkey.in  2026-09-21 19:36:47.000000000 
+0200
++++ b/zkey/initramfs/hooks/s390-tools-zkey.in  2026-09-22 10:02:57.271515356 
+0200
 @@ -29,7 +29,7 @@
  . /usr/share/initramfs-tools/hook-functions
  

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/s390-tools/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.s390-tools.new.383539/vendor.tar.zst differ: char 
7, line 1

Reply via email to