Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package binaryen for openSUSE:Factory checked in at 2026-09-29 17:48:09 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/binaryen (Old) and /work/SRC/openSUSE:Factory/.binaryen.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "binaryen" Tue Sep 29 17:48:09 2026 rev:2 rq:1381193 version:133 Changes: -------- --- /work/SRC/openSUSE:Factory/binaryen/binaryen.changes 2025-06-26 11:38:44.824349556 +0200 +++ /work/SRC/openSUSE:Factory/.binaryen.new.383539/binaryen.changes 2026-09-29 17:48:44.110597657 +0200 @@ -1,0 +2,38 @@ +Mon Sep 28 14:19:02 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 133: + * CVE-2025-14956: heap buffer overflow when reading an expression + from a truncated binary (boo#1255447) + * CVE-2025-14957: NULL pointer dereference on an out-of-range + local index (boo#1255448) + * CVE-2026-8257: reachable assertion when parsing br_on* with a + non-reference operand (boo#1264834) + * New optimization passes and tool flags: constraint analysis + (runs automatically at -O3/-Os and above), --tail-call, + RemoveExports, MarkJSCalled, --remove-relaxed-simd, + --strip-toolchain-annotations + * Removed the --mod-asyncify-never-unwind and + --mod-asyncify-always-and-only-unwind passes + * wasm-split --multi-split uses placeholders unless + --no-placeholders is given + * WebAssembly proposal support: custom page sizes, relaxed + atomics, wide arithmetic, acqrel fences, multibyte arrays and + non-nullable table types + * Breaking C API changes: BinaryenAddTable takes an initialiser + expression, BinaryenAtomicFence takes a memory order, the + memory-segment accessors are renamed to BinaryenGetDataSegment* + and take a BinaryenDataSegmentRef, setAtomic is replaced by + setMemoryOrder, and the relaxed-SIMD functions are renamed + * Built with C++20 instead of C++17 + * Many more fixes and improvements; see upstream's release notes + for the full list +- Declare the licences of the bundled LLVM (Apache-2.0 WITH + LLVM-exception, NCSA, Unicode-DFS-2015, bcrypt-Solar-Designer) + and FP16 (MIT) code compiled into libbinaryen +- Spec cleanup: + * Drop the deprecated Group tags and the -pthread CMakeLists.txt + hack, upstream links Threads::Threads + * Drop the stray rm of debug files from %postun + * Add the upstream cmake >= 3.16.3 floor + +------------------------------------------------------------------- Old: ---- _scmsync.obsinfo binaryen-version_123.tar.gz build.specials.obscpio New: ---- binaryen-version_133.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ binaryen.spec ++++++ --- /var/tmp/diff_new_pack.qYwoDG/_old 2026-09-29 17:48:46.472695857 +0200 +++ /var/tmp/diff_new_pack.qYwoDG/_new 2026-09-29 17:48:46.474695940 +0200 @@ -1,7 +1,7 @@ # # spec file for package binaryen # -# Copyright (c) 2025 SUSE LLC +# Copyright (c) 2026 SUSE LLC and contributors # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,15 +17,25 @@ Name: binaryen -Version: 123 +Version: 133 Release: 0 Summary: Compiler infrastructure and toolchain library for WebAssembly -License: Apache-2.0 -# FIXME: use correct group or remove it, see "https://en.opensuse.org/openSUSE:Package_group_guidelines" -Group: Development/Tools +# Legal-Review-Notice: code compiled in besides upstream's Apache-2.0: +# - third_party/llvm-project (DWARF support, BUILD_LLVM_DWARF is ON by +# default) and src/support/suffix_tree*.cpp (always built) are +# Apache-2.0 WITH LLVM-exception; llvm-project's MD5.cpp is +# bcrypt-Solar-Designer and its ConvertUTF.cpp carries the +# Unicode-DFS-2015 notice. The bundled include/llvm/LICENSE.TXT keeps +# the legacy University of Illinois/NCSA licence for pre-relicensing +# LLVM code, and the compiled Support sources fall under it: NCSA. +# - The header-only third_party/FP16 is MIT. +# - The other third_party trees are empty submodules or unused by the +# build (wabt/wasm2c only serves the fuzzer scripts), and +# BUILD_MIMALLOC defaults to OFF. +License: Apache-2.0 AND Apache-2.0 WITH LLVM-exception AND MIT AND NCSA AND Unicode-DFS-2015 AND bcrypt-Solar-Designer URL: https://github.com/WebAssembly/binaryen Source: https://github.com/WebAssembly/binaryen/archive/version_%{version}.tar.gz#/%{name}-version_%{version}.tar.gz -BuildRequires: cmake +BuildRequires: cmake >= 3.16.3 BuildRequires: gcc BuildRequires: gcc-c++ BuildRequires: pkgconfig @@ -67,16 +77,12 @@ %package -n lib%{name} Summary: Library for %{name} -# FIXME: use correct group or remove it, see "https://en.opensuse.org/openSUSE:Package_group_guidelines" -Group: Development/Tools %description -n lib%{name} Library for %{name}. %package -n lib%{name}-devel Summary: Development files for lib%{name} -# FIXME: use correct group or remove it, see "https://en.opensuse.org/openSUSE:Package_group_guidelines" -Group: Development/Tools Requires: lib%{name} = %{version} %description -n lib%{name}-devel @@ -84,10 +90,6 @@ %prep %autosetup -n %{name}-version_%{version} -# fix pthread link error -cat >> "./CMakeLists.txt" <<-EOF -SET(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -pthread") -EOF %build %cmake \ @@ -101,9 +103,6 @@ %post -n lib%{name} -p /sbin/ldconfig %postun -n lib%{name} -p /sbin/ldconfig -rm %{buildroot}%{_prefix}/lib/debug/usr/bin/wasm-merge.debug -rm %{buildroot}%{_prefix}/lib/debug/usr/bin/wasm-fuzz-lattices.debug - %files %license LICENSE %doc README.md Contributing.md ++++++ binaryen-version_123.tar.gz -> binaryen-version_133.tar.gz ++++++ /work/SRC/openSUSE:Factory/binaryen/binaryen-version_123.tar.gz /work/SRC/openSUSE:Factory/.binaryen.new.383539/binaryen-version_133.tar.gz differ: char 13, line 1
