Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-pyspnego for openSUSE:Factory 
checked in at 2026-10-01 16:44:08
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-pyspnego (Old)
 and      /work/SRC/openSUSE:Factory/.python-pyspnego.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-pyspnego"

Thu Oct  1 16:44:08 2026 rev:23 rq:1381659 version:0.12.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-pyspnego/python-pyspnego.changes  
2026-09-04 12:38:40.786937976 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-pyspnego.new.1253/python-pyspnego.changes    
    2026-10-01 16:45:14.236494393 +0200
@@ -1,0 +2,9 @@
+Wed Sep 30 07:46:47 UTC 2026 - Martin Hauke <[email protected]>
+
+- Update to version 0.12.3
+  * Fix NTLM acceptor to include the Version field in the CHALLENGE
+    message when NTLMSSP_NEGOTIATE_VERSION is negotiated.
+    + Strict initiators like gss-ntlmssp failed to decode the
+      message as the field offsets were 8 bytes too early.
+
+-------------------------------------------------------------------

Old:
----
  pyspnego-0.12.2.tar.gz

New:
----
  pyspnego-0.12.3.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-pyspnego.spec ++++++
--- /var/tmp/diff_new_pack.Zdqidy/_old  2026-10-01 16:45:14.961524786 +0200
+++ /var/tmp/diff_new_pack.Zdqidy/_new  2026-10-01 16:45:14.966524996 +0200
@@ -23,7 +23,7 @@
 %endif
 %{?sle15_python_module_pythons}
 Name:           python-pyspnego
-Version:        0.12.2
+Version:        0.12.3
 Release:        0
 Summary:        Python SPNEGO authentication library
 License:        MIT

++++++ pyspnego-0.12.2.tar.gz -> pyspnego-0.12.3.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pyspnego-0.12.2/.github/workflows/ci.yml 
new/pyspnego-0.12.3/.github/workflows/ci.yml
--- old/pyspnego-0.12.2/.github/workflows/ci.yml        2026-08-26 
07:00:47.000000000 +0200
+++ new/pyspnego-0.12.3/.github/workflows/ci.yml        2026-09-29 
23:12:38.000000000 +0200
@@ -48,7 +48,6 @@
       matrix:
         os:
         - ubuntu-latest
-        - macOS-15-intel
         - macOS-latest
         - windows-latest
         python-version:
@@ -73,13 +72,6 @@
         - os: ubuntu-latest
           gssapi-provider: sspi
 
-        - os: macOS-15-intel
-          python-arch: arm64
-        - os: macOS-15-intel
-          gssapi-provider: mit
-        - os: macOS-15-intel
-          gssapi-provider: sspi
-
         - os: macOS-latest
           python-arch: x64
         - os: macOS-latest
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pyspnego-0.12.2/CHANGELOG.md 
new/pyspnego-0.12.3/CHANGELOG.md
--- old/pyspnego-0.12.2/CHANGELOG.md    2026-08-26 07:00:47.000000000 +0200
+++ new/pyspnego-0.12.3/CHANGELOG.md    2026-09-29 23:12:38.000000000 +0200
@@ -1,5 +1,10 @@
 # Changelog
 
+## 0.12.3 - 2026-09-30
+
+* Fix NTLM acceptor to include the `Version` field in the `CHALLENGE` message 
when `NTLMSSP_NEGOTIATE_VERSION` is negotiated
+  * Strict initiators like `gss-ntlmssp` failed to decode the message as the 
field offsets were 8 bytes too early
+
 ## 0.12.2 - 2026-08-26
 
 * Fix up NTLM single host data unpacking to be less strict making it 
compatible with newer Windows versions
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pyspnego-0.12.2/src/spnego/_ntlm.py 
new/pyspnego-0.12.3/src/spnego/_ntlm.py
--- old/pyspnego-0.12.2/src/spnego/_ntlm.py     2026-08-26 07:00:47.000000000 
+0200
+++ new/pyspnego-0.12.3/src/spnego/_ntlm.py     2026-09-29 23:12:38.000000000 
+0200
@@ -526,7 +526,19 @@
         target_info[AvId.dns_computer_name] = to_text(socket.getfqdn())
         target_info[AvId.timestamp] = FileTime.now()
 
-        challenge = Challenge(flags, server_challenge, 
target_name=target_name, target_info=target_info)
+        # The Version field is only present when the flag is set, strict
+        # decoders like gss-ntlmssp reject the message if it is missing.
+        challenge_kwargs: typing.Dict[str, typing.Any] = {}
+        if flags & NegotiateFlags.version:
+            challenge_kwargs["version"] = Version.get_current()
+
+        challenge = Challenge(
+            flags,
+            server_challenge,
+            target_name=target_name,
+            target_info=target_info,
+            **challenge_kwargs,
+        )
 
         self._temp_negotiate = negotiate
         self._temp_challenge = challenge
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pyspnego-0.12.2/src/spnego/_version.py 
new/pyspnego-0.12.3/src/spnego/_version.py
--- old/pyspnego-0.12.2/src/spnego/_version.py  2026-08-26 07:00:47.000000000 
+0200
+++ new/pyspnego-0.12.3/src/spnego/_version.py  2026-09-29 23:12:38.000000000 
+0200
@@ -1,4 +1,4 @@
 # Copyright: (c) 2020, Jordan Borean (@jborean93) <[email protected]>
 # MIT License (see LICENSE or https://opensource.org/licenses/MIT)
 
-__version__ = "0.12.2"
+__version__ = "0.12.3"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pyspnego-0.12.2/tests/test_ntlm.py 
new/pyspnego-0.12.3/tests/test_ntlm.py
--- old/pyspnego-0.12.2/tests/test_ntlm.py      2026-08-26 07:00:47.000000000 
+0200
+++ new/pyspnego-0.12.3/tests/test_ntlm.py      2026-09-29 23:12:38.000000000 
+0200
@@ -428,6 +428,28 @@
         n._step_accept_negotiate(negotiate.tobytes())
 
 
[email protected]("version", [True, False])
+def test_ntlm_accept_challenge_version(version):
+    flags = NegotiateFlags.unicode | NegotiateFlags.ntlm | 
NegotiateFlags.extended_session_security
+    if version:
+        flags |= NegotiateFlags.version
+    negotiate = Negotiate(flags)
+    assert bool(negotiate.flags & NegotiateFlags.version) == version
+
+    n = ntlm.NTLMProxy("user", "pass")
+    challenge = Challenge.unpack(n._step_accept_negotiate(negotiate.pack()))
+
+    # The payload must start after the Version field when the flag is set.
+    if version:
+        assert challenge.flags & NegotiateFlags.version
+        assert challenge.version == Version.get_current()
+        assert challenge._payload_offset == 56
+    else:
+        assert challenge.flags & NegotiateFlags.version == 0
+        assert challenge.version is None
+        assert challenge._payload_offset == 48
+
+
 @pytest.mark.parametrize(
     "client_opt, present",
     [

Reply via email to