Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-pyspnego for openSUSE:Factory
checked in at 2026-10-01 16:44:08
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-pyspnego (Old)
and /work/SRC/openSUSE:Factory/.python-pyspnego.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-pyspnego"
Thu Oct 1 16:44:08 2026 rev:23 rq:1381659 version:0.12.3
Changes:
--------
--- /work/SRC/openSUSE:Factory/python-pyspnego/python-pyspnego.changes
2026-09-04 12:38:40.786937976 +0200
+++
/work/SRC/openSUSE:Factory/.python-pyspnego.new.1253/python-pyspnego.changes
2026-10-01 16:45:14.236494393 +0200
@@ -1,0 +2,9 @@
+Wed Sep 30 07:46:47 UTC 2026 - Martin Hauke <[email protected]>
+
+- Update to version 0.12.3
+ * Fix NTLM acceptor to include the Version field in the CHALLENGE
+ message when NTLMSSP_NEGOTIATE_VERSION is negotiated.
+ + Strict initiators like gss-ntlmssp failed to decode the
+ message as the field offsets were 8 bytes too early.
+
+-------------------------------------------------------------------
Old:
----
pyspnego-0.12.2.tar.gz
New:
----
pyspnego-0.12.3.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-pyspnego.spec ++++++
--- /var/tmp/diff_new_pack.Zdqidy/_old 2026-10-01 16:45:14.961524786 +0200
+++ /var/tmp/diff_new_pack.Zdqidy/_new 2026-10-01 16:45:14.966524996 +0200
@@ -23,7 +23,7 @@
%endif
%{?sle15_python_module_pythons}
Name: python-pyspnego
-Version: 0.12.2
+Version: 0.12.3
Release: 0
Summary: Python SPNEGO authentication library
License: MIT
++++++ pyspnego-0.12.2.tar.gz -> pyspnego-0.12.3.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/pyspnego-0.12.2/.github/workflows/ci.yml
new/pyspnego-0.12.3/.github/workflows/ci.yml
--- old/pyspnego-0.12.2/.github/workflows/ci.yml 2026-08-26
07:00:47.000000000 +0200
+++ new/pyspnego-0.12.3/.github/workflows/ci.yml 2026-09-29
23:12:38.000000000 +0200
@@ -48,7 +48,6 @@
matrix:
os:
- ubuntu-latest
- - macOS-15-intel
- macOS-latest
- windows-latest
python-version:
@@ -73,13 +72,6 @@
- os: ubuntu-latest
gssapi-provider: sspi
- - os: macOS-15-intel
- python-arch: arm64
- - os: macOS-15-intel
- gssapi-provider: mit
- - os: macOS-15-intel
- gssapi-provider: sspi
-
- os: macOS-latest
python-arch: x64
- os: macOS-latest
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/pyspnego-0.12.2/CHANGELOG.md
new/pyspnego-0.12.3/CHANGELOG.md
--- old/pyspnego-0.12.2/CHANGELOG.md 2026-08-26 07:00:47.000000000 +0200
+++ new/pyspnego-0.12.3/CHANGELOG.md 2026-09-29 23:12:38.000000000 +0200
@@ -1,5 +1,10 @@
# Changelog
+## 0.12.3 - 2026-09-30
+
+* Fix NTLM acceptor to include the `Version` field in the `CHALLENGE` message
when `NTLMSSP_NEGOTIATE_VERSION` is negotiated
+ * Strict initiators like `gss-ntlmssp` failed to decode the message as the
field offsets were 8 bytes too early
+
## 0.12.2 - 2026-08-26
* Fix up NTLM single host data unpacking to be less strict making it
compatible with newer Windows versions
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/pyspnego-0.12.2/src/spnego/_ntlm.py
new/pyspnego-0.12.3/src/spnego/_ntlm.py
--- old/pyspnego-0.12.2/src/spnego/_ntlm.py 2026-08-26 07:00:47.000000000
+0200
+++ new/pyspnego-0.12.3/src/spnego/_ntlm.py 2026-09-29 23:12:38.000000000
+0200
@@ -526,7 +526,19 @@
target_info[AvId.dns_computer_name] = to_text(socket.getfqdn())
target_info[AvId.timestamp] = FileTime.now()
- challenge = Challenge(flags, server_challenge,
target_name=target_name, target_info=target_info)
+ # The Version field is only present when the flag is set, strict
+ # decoders like gss-ntlmssp reject the message if it is missing.
+ challenge_kwargs: typing.Dict[str, typing.Any] = {}
+ if flags & NegotiateFlags.version:
+ challenge_kwargs["version"] = Version.get_current()
+
+ challenge = Challenge(
+ flags,
+ server_challenge,
+ target_name=target_name,
+ target_info=target_info,
+ **challenge_kwargs,
+ )
self._temp_negotiate = negotiate
self._temp_challenge = challenge
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/pyspnego-0.12.2/src/spnego/_version.py
new/pyspnego-0.12.3/src/spnego/_version.py
--- old/pyspnego-0.12.2/src/spnego/_version.py 2026-08-26 07:00:47.000000000
+0200
+++ new/pyspnego-0.12.3/src/spnego/_version.py 2026-09-29 23:12:38.000000000
+0200
@@ -1,4 +1,4 @@
# Copyright: (c) 2020, Jordan Borean (@jborean93) <[email protected]>
# MIT License (see LICENSE or https://opensource.org/licenses/MIT)
-__version__ = "0.12.2"
+__version__ = "0.12.3"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/pyspnego-0.12.2/tests/test_ntlm.py
new/pyspnego-0.12.3/tests/test_ntlm.py
--- old/pyspnego-0.12.2/tests/test_ntlm.py 2026-08-26 07:00:47.000000000
+0200
+++ new/pyspnego-0.12.3/tests/test_ntlm.py 2026-09-29 23:12:38.000000000
+0200
@@ -428,6 +428,28 @@
n._step_accept_negotiate(negotiate.tobytes())
[email protected]("version", [True, False])
+def test_ntlm_accept_challenge_version(version):
+ flags = NegotiateFlags.unicode | NegotiateFlags.ntlm |
NegotiateFlags.extended_session_security
+ if version:
+ flags |= NegotiateFlags.version
+ negotiate = Negotiate(flags)
+ assert bool(negotiate.flags & NegotiateFlags.version) == version
+
+ n = ntlm.NTLMProxy("user", "pass")
+ challenge = Challenge.unpack(n._step_accept_negotiate(negotiate.pack()))
+
+ # The payload must start after the Version field when the flag is set.
+ if version:
+ assert challenge.flags & NegotiateFlags.version
+ assert challenge.version == Version.get_current()
+ assert challenge._payload_offset == 56
+ else:
+ assert challenge.flags & NegotiateFlags.version == 0
+ assert challenge.version is None
+ assert challenge._payload_offset == 48
+
+
@pytest.mark.parametrize(
"client_opt, present",
[