Please note that this mail was generated by a script.
The described changes are computed based on the aarch64 DVD.
The full online repo contains too many changes to be listed here.

Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=3&version=Tumbleweed&build=20200612

Please do not reply to this email to report issues, rather file a bug
on bugzilla.opensuse.org. For more information on filing bugs please
see https://en.opensuse.org/openSUSE:Submitting_bug_reports

Packages changed:
  ImageMagick (7.0.10.13 -> 7.0.10.18)
  alsa (1.2.2 -> 1.2.3)
  alsa-ucm-conf (1.2.2 -> 1.2.3)
  alsa-utils (1.2.2 -> 1.2.3)
  audit
  bluez-tools
  busybox-links
  ceph (15.2.0.108+g8cf4f02b08 -> 15.2.3.252+gf2237253cd)
  cogl (1.22.6 -> 1.22.8)
  dracut (050+suse.65.ge1e64674 -> 050+suse.66.g76431c83)
  drbd (9.0.22~1+git.fe2b5983 -> 9.0.23~1+git.d16bfab7)
  elementary-xfce-icon-theme (0.15+git6.098bd333 -> 0.15+git8.ae895abc)
  evince (3.36.2 -> 3.36.3)
  ffmpeg-4 (4.2.2 -> 4.2.3)
  fonts-config (20190119 -> 20200609+git0.42e2b1b)
  ghostscript-fonts
  git (2.26.2 -> 2.27.0)
  gmp
  gnome-software
  gnutls (3.6.13 -> 3.6.14)
  gstreamer
  hunspell
  hwdata (0.335 -> 0.336)
  icedtea-web (1.7.2 -> 1.8)
  icu
  iptraf-ng (1.1.4 -> 1.2.0)
  kernel-64kb (5.6.14 -> 5.7.1)
  kernel-source (5.6.14 -> 5.7.1)
  konsole
  krb5 (1.18.1 -> 1.18.2)
  ksysguard5 (5.19.0 -> 5.19.0.1)
  libgpg-error (1.37 -> 1.38)
  libjcat (0.1.2 -> 0.1.2+3)
  libksysguard5 (5.19.0 -> 5.19.0.1)
  libnftnl (1.1.6 -> 1.1.7)
  libosinfo (1.7.1 -> 1.8.0)
  libqt5-qtbase
  librsvg (2.48.4 -> 2.48.7)
  libseccomp (2.4.2 -> 2.4.3)
  libupnp
  libxml2
  libxml2-python
  libzip (1.6.1 -> 1.7.0)
  man-pages (5.06 -> 5.07)
  mariadb (10.4.12 -> 10.4.13)
  memcached (1.6.5 -> 1.6.6)
  mozjs68 (68.7.0 -> 68.9.0)
  multipath-tools (0.8.4+31+suse.8f53764 -> 0.8.4+43+suse.908383f)
  ncurses (6.2.20200502 -> 6.2.20200531)
  newt
  nfs-utils
  nftables (0.9.4 -> 0.9.5)
  nodejs-common (3.0 -> 4.0)
  open-iscsi
  openssh (8.1p1 -> 8.3p1)
  osinfo-db (20200214 -> 20200529)
  package-update-indicator
  patterns-base
  perl
  perl-CGI (4.48 -> 4.49)
  perl-Date-Manip (6.81 -> 6.82)
  perl-Mojolicious (8.52 -> 8.53)
  perl-libwww-perl (6.44 -> 6.45)
  permissions (1550_20200520 -> 1550_20200526)
  pidgin (2.13.0 -> 2.14.0)
  postgresql
  postgresql12 (12.2 -> 12.3)
  powertop (2.12 -> 2.13)
  pulseaudio
  purge-kernels-service
  python
  python-base
  python-greenlet (0.4.15 -> 0.4.16)
  python-passlib
  python-ptyprocess
  python-rpm-macros (20200207.5feb6c1 -> 20200529.b301e36)
  python3
  python3-base
  redis (6.0.4 -> 6.0.5)
  remmina (1.4.5 -> 1.4.6)
  rubygem-nokogiri
  schily
  shadow
  sqlite3 (3.31.1 -> 3.32.2)
  sssd (2.2.3 -> 2.3.0)
  strace (5.6 -> 5.7)
  suse-module-tools (15.3.2 -> 15.3.3)
  systemd
  texlive
  timezone
  timezone-java
  uchardet (0.0.6 -> 0.0.7)
  util-linux
  util-linux-systemd
  vim
  wireless-regdb
  wireshark
  xdg-utils (1.1.3+20190413 -> 1.1.3+20200220)
  xdm
  xf86-input-wacom
  xterm
  yast2 (4.3.5 -> 4.3.6)
  yast2-add-on (4.3.0 -> 4.3.1)
  yast2-bootloader (4.3.3 -> 4.3.5)
  yast2-installation (4.3.1 -> 4.3.2)
  yast2-kdump (4.3.0 -> 4.3.1)
  yast2-proxy (4.3.0 -> 4.3.1)

=== Details ===

==== ImageMagick ====
Version update (7.0.10.13 -> 7.0.10.18)
Subpackages: ImageMagick-config-7-SUSE ImageMagick-extra libMagick++-7_Q16HDRI4 
libMagickCore-7_Q16HDRI7 libMagickWand-7_Q16HDRI7

- version update to 7.0.10.18
  * Colorspace change will remove ICC profile (reference
    https://github.com/ImageMagick/ImageMagick6/issues/82).
- version update to 7.0.10.17
  * Free up memory after a ICC profile is removed.
- version update to 7.0.10.16
  * Don't check for incompatible ICC profiles when writing PDF images, instead
    the user is expected to provide compatible image colorspaces or strip the
    ICC profile with, for example, the -strip option.
  * Clipping was not returning expected results (reference
    https://github.com/ImageMagick/ImageMagick/discussions/2061).
  * Don't write a ICC profile to PDF if the image is gray (reference
    https://github.com/ImageMagick/ImageMagick/issues/2070).

==== alsa ====
Version update (1.2.2 -> 1.2.3)
Subpackages: libasound2 libatopology2

- Update to alsa-lib 1.2.3:
  including previous fixes, see the detailed changes at:
  https://www.alsa-project.org/wiki/Detailed_changes_v1.2.2_v1.2.3
- Drop obsoleted patches:
  0001-conf-change-the-order-of-PCM-devices-in-alsa.conf.patch
  0002-conf-namehint-add-omit_noargs-to-the-hint-section.patch
  0003-Change-PCM-device-number-of-Asus-Xonar-U5.patch
  0004-configure-add-embed-for-python3-config-python-3.8.patch
  0005-conf-USB-Audio-Add-C-Media-USB-Headphone-Set-to-the-.patch
  0006-topology-add-back-asrc-to-widget_map-in-dapm.c.patch
  0007-ucm-clarify-the-index-syntax-for-the-device-names.patch
  0008-ucm-fix-uc_mgr_scan_master_configs.patch
  0009-namehint-remember-the-direction-from-the-upper-level.patch
  0010-conf-fix-namehint-for-pcm.front-and-pcm.iec958.patch
  0011-pcm-add-chmap-option-to-route-plugin.patch
  0012-usecase-allow-indexes-also-for-modifier-names.patch
  0013-ucm-fix-the-device-remove-operation.patch
  0014-ucm-fix-copy-n-paste-typo-RemoveDevice-list.patch
  0015-pcm-dmix-fix-sw_params-handling-of-timestamp-types-i.patch
  0016-conf-USB-Audio-Fix-S-PDIF-output-of-ASUS-Xonar-AE.patch
  0017-pcm-rate-fix-the-remaining-size-calculation-in-snd_p.patch
  0018-use-case.h-add-USB-as-allowed-device-name.patch
  0019-topology-Use-bool-parser-to-parse-boolean-value.patch
  0020-fix-infinite-draining-of-the-rate-plugin-in-SND_PCM_.patch
  0021-test-pcm_min-add-snd_pcm_drain-call-and-indentation-.patch

==== alsa-ucm-conf ====
Version update (1.2.2 -> 1.2.3)

- Update to alsa-ucm-conf 1.2.3:
  including previous fixes, see the detailed changes at:
  https://www.alsa-project.org/wiki/Detailed_changes_v1.2.2_v1.2.3
- Dropped obsoleted patches:
  0001-sof-bdw-rt5677-initial-port-to-UCM2.patch
  0002-ucm2-treewide-JackHWMute-fixes.patch
  0003-sof-hda-dsp-Support-systems-without-integrated-graph.patch
  0004-hda-dsp-add-basic-ucm-config.patch
  0005-update-README-files.patch
  0006-bytcr-rt5651-Fix-dmic-check-in-HiFi-Components.conf.patch
  0007-chtrt5645-Add-ASUSTeKCOMPUTERINC.-T100HAN-1.0-symlin.patch
  0008-chtrt5645-Add-MEDION-E1239TMD60568-0.1-Wingman.conf-.patch
  0009-chtrt5645-Remove-bogus-JackHWMute-settings.patch
  0010-sof-hda-dsp-change-Headphones2-to-Mic2.patch
  0011-ucm2-remove-empty-enable-disable-sequence-sections.patch
  0012-ucm2-fix-indentation-use-tabs.patch
  0013-Add-initial-support-for-Realtek-ALC1220-TRX40-mother.patch
  0014-ucm2-fix-chtrt5650-configuration-ucm-validator.patch
  0015-bytcr-rt5651-fix-the-cfg-mic-in1-cfg-mic-in12-match-.patch
  0016-ucm-fix-wrong-If-in-sequence-in-HiFi-dual.conf.patch
  0100-ucm2-Add-profile-for-Chromebook-Asus-C300.patch

==== alsa-utils ====
Version update (1.2.2 -> 1.2.3)

- Update to alsa-utils 1.2.3:
  including previous fixes, see the detailed changes at:
  https://www.alsa-project.org/wiki/Detailed_changes_v1.2.2_v1.2.3
- Dropped obsoleted patches:
  0001-alsaloop-reduce-cumulative-error-caused-by-non-atomi.patch
  0002-alsactl-don-t-exit-on-EINTR-from-epoll_wait.patch
  0003-alsactl-avoid-needless-wakeups-in-monitor-loop.patch
  0004-alsactl-fix-error-handling-for-sched_setscheduler-ca.patch
  0005-alsa-info.sh-add-ALT-to-DISTRO-list.patch
  0006-alsa-info-initial-rpm-deb-package-info.patch
  0007-alsa-info.sh-increase-version-to-0.4.65.patch

==== audit ====
Subpackages: audit-devel libaudit1 libauparse0

- Fix specfile to require libauparse0 and libaudit1 after splitting
  audit-libs (bsc#1172295)

==== bluez-tools ====

- Fix building with gcc10

==== busybox-links ====
Subpackages: busybox-bzip2 busybox-coreutils busybox-findutils busybox-gawk 
busybox-grep busybox-patch busybox-psmisc busybox-sed busybox-tar busybox-xz

- Create own busybox-adduser sub-package
- Add conflicts: mawk to busybox-gawk

==== ceph ====
Version update (15.2.0.108+g8cf4f02b08 -> 15.2.3.252+gf2237253cd)
Subpackages: librados2 librbd1

- Up ceph-test disk constraint to address "no space left on device"
  build error seen in OBS
- Update to 15.2.3-252-gf2237253cd:
  + rebase on tip of upstream "octopus" branch, SHA1 
22279597fa9ca40ba2f05af9f186a99ce73a6047
  * upstream v15.2.3 release
    https://ceph.io/releases/v15-2-3-octopus-released/
- Update to 15.2.2-60-gf5864377ab:
  + rebase on tip of upstream "octopus" branch, SHA1 
9e890709ef53ce29006c6fc754dd80e25df186d0
- Update to 15.2.2-18-g1dbcddb5d8:
  + rebase on tip of upstream "octopus" branch, SHA1 
0c857e985a29d90501a285f242ea9c008df49eb8
  * Upstream v15.2.2 release
    https://ceph.io/releases/v15-2-2-octopus-released/
  * mon, mgr: require all caps for pre-octopus tell commands (bsc#1170021, 
CVE-2020-10736)
- Update to 15.2.1-277-g17d346932e:
  + rebase on tip of upstream "octopus" branch, SHA1 
752b293586d0c8749483e60e43c7a98c1e0d7b19
  * rpm: drop "is_opensuse" conditional in SUSE-specific bcond block
    (jsc#SLE-11802)
- Update to 15.2.1-246-g66cd0e5497:
  + rebase on tip of upstream "octopus" branch, SHA1 
939661f696d3d9eb4d31e998a3ad1487852a4741
- Update to 15.2.1-16-gb3a86250a6:
  + rebase on tip of upstream "octopus" branch, SHA1 
9fd2f65f91d9246fae2c841a6222d34d121680ee
  * upstream 15.2.1 release
    https://ceph.io/releases/v15-2-1-octopus-released/
    + fix Nonce reuse in msgr V2 secure mode (bsc#1166403, CVE-2020-1759)
    + prevent RGW GetObject header-splitting XSS (bsc#1166484, CVE-2020-1760)

==== cogl ====
Version update (1.22.6 -> 1.22.8)
Subpackages: libcogl-pango20 libcogl20 typelib-1_0-Cogl-1_0 
typelib-1_0-CoglPango-1_0

- Update to version 1.22.8:
  + Fix building against libglvnd-provided EGL headers.
  + Stop checking the Automake version.
  + Fix compiler warnings with GCC ? 9.
  + Ensure we don't close the same X display twice.
  + Test suite fixes.
  + Free pipeline state last.
- Drop cogl-fix-mesa20.patch: Fixed upstream. Following this, drop
  libtool BuildRequires and autoreconf call, no longer needed.

==== dracut ====
Version update (050+suse.65.ge1e64674 -> 050+suse.66.g76431c83)

- Update to version 050+suse.66.g76431c83:
  * 95iscsi: fix missing space when compiling cmdline args (bsc#1172816)

==== drbd ====
Version update (9.0.22~1+git.fe2b5983 -> 9.0.23~1+git.d16bfab7)
Subpackages: drbd-kmp-64kb drbd-kmp-default

- bsc#1172761, Update to drbd-9.0.23-1
  * fix a deadlock (regression introduced in 9.0.22) that can happen when
  new current UUID is generated while a connection gets established
  * Do not create a new data generation if the node has
  'allow-remote-read = no' set, is primary, and the local disk fails
  (because it has no access to good data anyome)
  * fix a deadlock (regression introduced in 9.0.22) that can be
  triggered if a minor is added into a resource with an established
  connection
  * generate new UUID immediately if a primary loses a disk due to an IO
  error
  * fix read requests on diskless nodes that hit a read error on a
  diskful node; the retry on another diskful node works, but a bug
  could lead to a log-storm on the diskless node
  * fix removal of diskless nodes from clusters with quorum enabled
  (initiated from the diskless itself)
  * fix wrongly declined state changes if connections are established
  concurrently
  * fix continuation of initial resync; before that the initial resync
  always started from the beginning if it was interrupted
  * use rwsem _non_owner() operations to avoid false positives of
  lock-dep when running on a debug kernel
  * fix a sometimes missed resync if only a diskless node was primary
  since the day0 UUID
  * fix a corner case where a SyncSource node does not recognise
  that a SyncTarget node declared the resync as finished
  * update compat up to Linux 5.6
- Remove patch without_pr_warning.patch since change in 7e6a20f7
- jsc#11801, enable buildrt for Leap15.2 but Tumbleweed.

==== elementary-xfce-icon-theme ====
Version update (0.15+git6.098bd333 -> 0.15+git8.ae895abc)

- Update to version 0.15+git8.ae895abc:
  * Fixed nm-applet icon in  notification bubble and vpn indicator
    lock (issue #212)
  * Fixed several contrast problems and added new colored
    software-update icons

==== evince ====
Version update (3.36.2 -> 3.36.3)
Subpackages: evince-plugin-comicsdocument evince-plugin-djvudocument 
evince-plugin-dvidocument evince-plugin-pdfdocument evince-plugin-tiffdocument 
evince-plugin-xpsdocument libevdocument3-4 libevview3-3 nautilus-evince 
typelib-1_0-EvinceDocument-3_0 typelib-1_0-EvinceView-3_0

- Update to version 3.36.3:
  + pdf: Revert "support 'de facto' tooltip feature"
    (glgo#GNOME/evince#1414). Reopens issues
    (glgo#GNOME/evince#1409 and glgo#GNOME/evince#1410).

==== ffmpeg-4 ====
Version update (4.2.2 -> 4.2.3)
Subpackages: libavcodec58 libavdevice58 libavfilter7 libavformat58 
libavresample4 libavutil56 libpostproc55 libswresample3 libswscale5

- Update to version 4.2.3:
  * Stable bug fix release, mainly codecs and format fixes.
- Drop 0001-avcodec-cbs_jpeg-Check-length-for-SOS.patch: Fixed
  upstream.

==== fonts-config ====
Version update (20190119 -> 20200609+git0.42e2b1b)

- Add a _service file
- Add code in %post to check the value of
  FORCE_MODIFY_DEFAULT_FONT_SETTINGS_IN_NEXT_UPDATE and if it's
  set to yes, empty or it doesn't exist, then update the values
  of FORCE_HINTSTYLE, USE_LCDFILTER and USE_RGBA in
  /etc/sysconfig/fonts-config to use the default settings
  established in the 20181211 release (boo#1172022)
- Update to 20200609+git0.42e2b1b:
  * Add variable to allow fonts-config to update default settings
  * Fix en-US, en-GB font matching

==== ghostscript-fonts ====
Subpackages: ghostscript-fonts-other ghostscript-fonts-std

- Add a ghostscript-fonts-std-converted subpackage with fonts from
  ghostscript-fonts-std converted to TrueType format (boo#1169444)

==== git ====
Version update (2.26.2 -> 2.27.0)
Subpackages: git-core git-cvs git-daemon git-email git-gui git-svn git-web gitk

- git 2.27.0:
  * "git describe" will always use the "long" version when giving
    its output based misplaced tags
  * "git pull" issues a warning message until the pull.rebase
    configuration variable is explicitly given
  * The transport protocol version 2, which was promoted to the
    default in Git 2.26 release, turned out to have some remaining
    rough edges, so it has been demoted from the default
  * A handful of options to configure SSL when talking to proxies
    have been added
  * Smudge/clean conversion filters are now given more information
  * many bug fixes, improvements, and additional workflow options
- drop upstreamed patches:
  * 0001-fetch-pack-return-enum-from-process_acks.patch
  * 0002-fetch-pack-in-protocol-v2-in_vain-only-after-ACK.patch
  * 0003-fetch-pack-in-protocol-v2-reset-in_vain-upon-ACK.patch
- drop unneeded patches:
  * 0001-DOC-Move-to-DocBook-5-when-using-asciidoctor.patch
  * 0002-Also-use-DocBook-5-stylesheet-when-generating-HTML-o.patch

==== gmp ====
Subpackages: gmp-devel libgmp10 libgmpxx4

- correct license statement (library itself is no GPL-3.0)

==== gnome-software ====

- Add gnome-software-failed-offline-update-notification.patch:
  plugin-loader: handle offline update errors properly(bsc#1161095,
  glgo#GNOME/gnome-software!471).

==== gnutls ====
Version update (3.6.13 -> 3.6.14)
Subpackages: libgnutls-dane0 libgnutls30 libgnutls30-hmac

- Fix a memory leak that could lead to a DoS attack against Samba
  servers (bsc#1172663)
  * add 0001-crypto-api-always-allocate-memory-when-serializing-i.patch
- Temporarily disable broken guile reauth test (bsc#1171565)
  * add gnutls-temporarily_disable_broken_guile_reauth_test
- Update to 3.6.14
  * libgnutls: Fixed insecure session ticket key construction, since 3.6.4.
    The TLS server would not bind the session ticket encryption key with a
    value supplied by the application until the initial key rotation, allowing
    attacker to bypass authentication in TLS 1.3 and recover previous
    conversations in TLS 1.2 (#1011). (bsc#1172506, CVE-2020-13777)
    [GNUTLS-SA-2020-06-03, CVSS: high]
  * libgnutls: Fixed handling of certificate chain with cross-signed
    intermediate CA certificates (#1008). (bsc#1172461)
  * libgnutls: Fixed reception of empty session ticket under TLS 1.2 (#997).
  * libgnutls: gnutls_x509_crt_print() is enhanced to recognizes commonName
    (2.5.4.3), decodes certificate policy OIDs (!1245), and prints Authority
    Key Identifier (AKI) properly (#989, #991).
  * certtool: PKCS #7 attributes are now printed with symbolic names (!1246).
  * libgnutls: Use accelerated AES-XTS implementation if possible (!1244).
    Also both accelerated and non-accelerated implementations check key block
    according to FIPS-140-2 IG A.9 (!1233).
  * libgnutls: Added support for AES-SIV ciphers (#463).
  * libgnutls: Added support for 192-bit AES-GCM cipher (!1267).
  * libgnutls: No longer use internal symbols exported from Nettle (!1235)
  * API and ABI modifications:
    GNUTLS_CIPHER_AES_128_SIV: Added
    GNUTLS_CIPHER_AES_256_SIV: Added
    GNUTLS_CIPHER_AES_192_GCM: Added
    gnutls_pkcs7_print_signature_info: Added
- Add key D605848ED7E69871: public key "Daiki Ueno <u...@unixuser.org>" to
  the keyring
- Drop gnutls-fips_correct_nettle_soversion.patch (upstream)

==== gstreamer ====
Subpackages: gstreamer-utils libgstreamer-1_0-0 typelib-1_0-Gst-1_0

- adjust / ship more 32bit stuff for Wine usage (bsc#1172304)

==== hunspell ====
Subpackages: hunspell-tools libhunspell-1_7-0

- security update
- added patches
  fix CVE-2019-16707 [bsc#1151867], invalid read operation in 
SuggestMgr:leftcommonsubstring in suggestmgr.cxx
  + hunspell-CVE-2019-16707.patch

==== hwdata ====
Version update (0.335 -> 0.336)

- Update to version 0.336:
  + Updated pci, usb and vendor ids.

==== icedtea-web ====
Version update (1.7.2 -> 1.8)
Subpackages: icedtea-web-javadoc

- Update to 1.8.0
  * added support for javafx-desc and so allowing run of pure javafx
    only applications
  * --nosecurity enhanced for possibility to skip invalid signatures
  * enhanced to allow resources to be read also from j2se/java
    element (OmegaT)
  * PR3644 - java.lang.NoClassDefFoundError: Could not initialize
    class net.sourceforge.jnlp.runtime
  .JNLPRuntime$DeploymentConfigurationHolder
  * deployment.config now support generic url instead just file
  * Added support for windows desktop shortcuts via
    https://github.com/DmitriiShamrikov/mslinks
  * cache can now be operated by groups, list by -Xcacheids (details
    via -verbose, can filter by regex), Xclearcache now can clear
    only selected id. There is also gui to operate cache via id in
    itweb-settings now.
  * desktop shortcut name get shortened to title or file if title is
    missing.
  * shared native launchers
  * scripted launchers rework: Windows bat launchers rewritten to be
    feature complete, Linux shell launchers made portable, build
    enhanced to produce platform independent image

==== icu ====
Subpackages: libicu67 libicu67-ledata

- Add the provides for libicu to Make .Net core can install
  successfully. (bsc#1167603, bsc#1161007)

==== iptraf-ng ====
Version update (1.1.4 -> 1.2.0)

- Update to release 1.2.0
  * A set of minor bugfixes.
  * Fix CPU hogging if the interface gets removed [rhbz#1572750]
- Drop iptraf-ng-1.1.4-fix-Floating-point-exception-in-tcplog_flowra.patch,
  build-use-wide-version-of-lpanel-when-needed.patch,
  0001-ifstats-make-sort-by-ifname-the-only-mode-of-operati.patch
  (merged)
- Add 0001-Revert-TPACKET_V3-mlock-mmap-ed-address-space-into-R.patch

==== kernel-64kb ====
Version update (5.6.14 -> 5.7.1)

- syscalls: fix offset type of ksys_ftruncate (bsc#1172699).
- commit 8d4977c
- armv7/ararch64: Update config files.
  Enable IOMMU_DEFAULT_PASSTHROUGH; per jsc#SLE-5568 this should be on by
  default, like on x86_64.
- commit bb34387
- Refresh
  patches.suse/jbd2-avoid-leaking-transaction-credits-when-unreserv.patch.
  Update upstream status.
- commit c3ae43f
- KVM: x86/mmu: Set mmio_value to '0' if reserved #PF can't be
  generated (bsc#1171904).
- KVM: x86: only do L1TF workaround on affected processors
  (bsc#1171904).
- commit 16721c7
- Linux 5.7.1 (bnc#1012628).
- airo: Fix read overflows sending packets (bnc#1012628).
- net: dsa: mt7530: set CPU port to fallback mode (bnc#1012628).
- media: staging: ipu3-imgu: Move alignment attribute to field
  (bnc#1012628).
- media: Revert "staging: imgu: Address a compiler warning on
  alignment" (bnc#1012628).
- mmc: fix compilation of user API (bnc#1012628).
- kernel/relay.c: handle alloc_percpu returning NULL in relay_open
  (bnc#1012628).
- crypto: api - Fix use-after-free and race in crypto_spawn_alg
  (bnc#1012628).
- mt76: mt76x02u: Add support for newer versions of the XBox
  One wifi adapter (bnc#1012628).
- p54usb: add AirVasT USB stick device-id (bnc#1012628).
- HID: i2c-hid: add Schneider SCL142ALM to descriptor override
  (bnc#1012628).
- HID: multitouch: enable multi-input as a quirk for some devices
  (bnc#1012628).
- HID: sony: Fix for broken buttons on DS3 USB dongles
  (bnc#1012628).
- mm: Fix mremap not considering huge pmd devmap (bnc#1012628).
- media: dvbdev: Fix tuner->demod media controller link
  (bnc#1012628).
- commit cc2f849
- config: refresh with gcc10
  gcc10 is default in Tumbleweed now.
- commit 0b1e86b
- Revert "Update config files."
  This reverts commit 34be040b91701c047e592935bc2dbb46a3947a56. We now
  have a fix (previous commit) in place, so change the configuration back
  (bsc#1156053).
- commit f4546fe
- usercopy: mark dma-kmalloc caches as usercopy caches
  (bsc#1156053).
- commit d3b5ce7
- jbd2: avoid leaking transaction credits when unreserving handle
  (bnc#1169774).
- commit 8599ef4
- jbd2: avoid leaking transaction credits when unreserving handle
  (bnc#1169774).
- Delete
  patches.suse/Revert-ext4-make-dioread_nolock-the-default.patch.
  Replace revert by the upstream fix.
- commit bfa465b
- Refresh
  patches.suse/drm-nouveau-Fix-regression-by-audio-component-transition.patch.
  Update upstream status.
- commit 3000ce5
- config: enable DEBUG_INFO_BTF
  This was disabled when the option was introduced in 5.2-rc1 but it turned
  out there are interesting use cases for having it enabled.
  Add pahole to build time dependencies as it is used to extracth the BTF
  data. Once we figure out how to make it conditional (only if DEBUG_INFO_BTF
  exists and is enabled), it should be done in packaging branch.
- commit 9ddab66
- Updated to 5.7 final
- refresh configs
- commit 7cd0da5
- Update config files.
- commit 6dba057
- Revert "virtio-balloon: Revert "virtio-balloon: Switch back to
  OOM handler for VIRTIO_BALLOON_F_DEFLATE_ON_OOM"" (virtio fix).
- commit fe7831e
- Linux 5.6.15 (bnc#1012628).
- blacklist.conf: remove one entry
- sched/fair: Fix enqueue_task_fair() warning some more
  (bnc#1012628).
- sched/fair: Fix reordering of enqueue/dequeue_task_fair()
  (bnc#1012628).
- sched/fair: Reorder enqueue/dequeue_task_fair path
  (bnc#1012628).
- bpf: Prevent mmap()'ing read-only maps as writable
  (bnc#1012628).
- rxrpc: Fix ack discard (bnc#1012628).
- rxrpc: Trace discarded ACKs (bnc#1012628).
- x86/unwind/orc: Fix unwind_get_return_address_ptr() for inactive
  tasks (bnc#1012628).
- flow_dissector: Drop BPF flow dissector prog ref on netns
  cleanup (bnc#1012628).
- s390/kexec_file: fix initrd location for kdump kernel
  (bnc#1012628).
- tpm: check event log version before reading final events
  (bnc#1012628).
- rxrpc: Fix a memory leak in rxkad_verify_response()
  (bnc#1012628).
- rxrpc: Fix the excessive initial retransmission timeout
  (bnc#1012628).
- iio: imu: st_lsm6dsx: unlock on error in
  st_lsm6dsx_shub_write_raw() (bnc#1012628).
- z3fold: fix use-after-free when freeing handles (bnc#1012628).
- sparc32: fix page table traversal in srmmu_nocache_init()
  (bnc#1012628).
- sparc32: use PUD rather than PGD to get PMD in
  srmmu_nocache_init() (bnc#1012628).
- sh: include linux/time_types.h for sockios (bnc#1012628).
- kasan: disable branch tracing for core runtime (bnc#1012628).
- rapidio: fix an error in get_user_pages_fast() error handling
  (bnc#1012628).
- device-dax: don't leak kernel memory to user space after
  unloading kmem (bnc#1012628).
- s390/kaslr: add support for R_390_JMP_SLOT relocation type
  (bnc#1012628).
- s390/pci: Fix s390_mmio_read/write with MIO (bnc#1012628).
- ipack: tpci200: fix error return code in tpci200_register()
  (bnc#1012628).
- mei: release me_cl object reference (bnc#1012628).
- tty: serial: add missing spin_lock_init for SiFive serial
  console (bnc#1012628).
- misc: rtsx: Add short delay after exit from ASPM (bnc#1012628).
- driver core: Fix handling of SYNC_STATE_ONLY + STATELESS device
  links (bnc#1012628).
- driver core: Fix SYNC_STATE_ONLY device link implementation
  (bnc#1012628).
- iio: adc: ti-ads8344: Fix channel selection (bnc#1012628).
- iio: dac: vf610: Fix an error handling path in
  'vf610_dac_probe()' (bnc#1012628).
- iio: sca3000: Remove an erroneous 'get_device()' (bnc#1012628).
- iio: adc: stm32-dfsdm: fix device used to request dma
  (bnc#1012628).
- iio: adc: stm32-adc: fix device used to request dma
  (bnc#1012628).
- staging: greybus: Fix uninitialized scalar variable
  (bnc#1012628).
- staging: kpc2000: fix error return code in kp2000_pcie_probe()
  (bnc#1012628).
- staging: wfx: unlock on error path (bnc#1012628).
- staging: iio: ad2s1210: Fix SPI reading (bnc#1012628).
- kbuild: Remove debug info from kallsyms linking (bnc#1012628).
- tools/bootconfig: Fix apply_xbc() to return zero on success
  (bnc#1012628).
- Revert "driver core: platform: Initialize dma_parms for platform
  devices" (bnc#1012628).
- virtio-balloon: Revert "virtio-balloon: Switch back to OOM
  handler for VIRTIO_BALLOON_F_DEFLATE_ON_OOM" (bnc#1012628).
- Revert "gfs2: Don't demote a glock until its revokes are
  written" (bnc#1012628).
- drm/i915: Propagate error from completed fences (bnc#1012628).
- drm/i915/gvt: Init DPLL/DDI vreg for virtual display instead
  of inheritance (bnc#1012628).
- vsprintf: don't obfuscate NULL and error pointers (bnc#1012628).
- dmaengine: owl: Use correct lock in owl_dma_get_pchan()
  (bnc#1012628).
- dmaengine: idxd: fix interrupt completion after unmasking
  (bnc#1012628).
- dmaengine: dmatest: Restore default for channel (bnc#1012628).
- drm/etnaviv: Fix a leak in submit_pin_objects() (bnc#1012628).
- dmaengine: tegra210-adma: Fix an error handling path in
  'tegra_adma_probe()' (bnc#1012628).
- apparmor: Fix aa_label refcnt leak in policy_update
  (bnc#1012628).
- apparmor: fix potential label refcnt leak in aa_change_profile
  (bnc#1012628).
- apparmor: Fix use-after-free in aa_audit_rule_init
  (bnc#1012628).
- pinctrl: qcom: Add affinity callbacks to msmgpio IRQ chip
  (bnc#1012628).
- drm/etnaviv: fix perfmon domain interation (bnc#1012628).
- powerpc/64s: Disable STRICT_KERNEL_RWX (bnc#1012628).
- arm64: Fix PTRACE_SYSEMU semantics (bnc#1012628).
- scsi: target: Put lun_ref at end of tmr processing
  (bnc#1012628).
- scsi: qla2xxx: Do not log message when reading port speed via
  sysfs (bnc#1012628).
- ALSA: hda/realtek - Add more fixup entries for Clevo machines
  (bnc#1012628).
- ALSA: hda/realtek - Fix silent output on Gigabyte X570 Aorus
  Xtreme (bnc#1012628).
- ALSA: pcm: fix incorrect hw_base increase (bnc#1012628).
- ALSA: iec1712: Initialize STDSP24 properly when using the
  model=staudio option (bnc#1012628).
- bpf: Add bpf_probe_read_{user, kernel}_str() to
  do_refine_retval_range (bnc#1012628).
- bpf: Restrict bpf_probe_read{, str}() only to archs where they
  work (bnc#1012628).
- Update config files.
- ALSA: hda/realtek: Enable headset mic of ASUS UX581LV with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek - Enable headset mic of ASUS UX550GE with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek - Enable headset mic of ASUS GL503VM with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek: Add quirk for Samsung Notebook (bnc#1012628).
- ALSA: hda/realtek - Add HP new mute led supported for ALC236
  (bnc#1012628).
- ALSA: hda/realtek - Add supported new mute Led for HP
  (bnc#1012628).
- scripts/gdb: repair rb_first() and rb_last() (bnc#1012628).
- tools/bootconfig: Fix resource leak in apply_xbc()
  (bnc#1012628).
- ARM: futex: Address build warning (bnc#1012628).
- KVM: selftests: Fix build for evmcs.h (bnc#1012628).
- drm/amd/display: Prevent dpcd reads with passive dongles
  (bnc#1012628).
- drm/amd/display: fix counter in wait_for_no_pipes_pending
  (bnc#1012628).
- iommu/amd: Call domain_flush_complete() in update_domain()
  (bnc#1012628).
- iommu/amd: Do not loop forever when trying to increase address
  space (bnc#1012628).
- platform/x86: asus-nb-wmi: Do not load on Asus T100TA and T200TA
  (bnc#1012628).
- USB: core: Fix misleading driver bug report (bnc#1012628).
- stmmac: fix pointer check after utilization in stmmac_interrupt
  (bnc#1012628).
- ceph: fix double unlock in handle_cap_export() (bnc#1012628).
- HID: quirks: Add HID_QUIRK_NO_INIT_REPORTS quirk for Dell K12A
  keyboard-dock (bnc#1012628).
- gtp: set NLM_F_MULTI flag in gtp_genl_dump_pdp() (bnc#1012628).
- x86/apic: Move TSC deadline timer debug printk (bnc#1012628).
- selftests: fix kvm relocatable native/cross builds and installs
  (bnc#1012628).
- ftrace/selftest: make unresolved cases cause failure if
  - -fail-unresolved set (bnc#1012628).
- ibmvnic: Skip fatal error reset after passive init
  (bnc#1012628).
- HID: i2c-hid: reset Synaptics SYNA2393 on resume (bnc#1012628).
- scsi: ibmvscsi: Fix WARN_ON during event pool release
  (bnc#1012628).
- net/ena: Fix build warning in ena_xdp_set() (bnc#1012628).
- component: Silence bind error on -EPROBE_DEFER (bnc#1012628).
- aquantia: Fix the media type of AQC100 ethernet controller in
  the driver (bnc#1012628).
- vhost/vsock: fix packet delivery order to monitoring devices
  (bnc#1012628).
- configfs: fix config_item refcnt leak in configfs_rmdir()
  (bnc#1012628).
- scsi: qla2xxx: Delete all sessions before unregister local
  nvme port (bnc#1012628).
- scsi: qla2xxx: Fix hang when issuing nvme disconnect-all in NPIV
  (bnc#1012628).
- HID: alps: ALPS_1657 is too specific; use U1_UNICORN_LEGACY
  instead (bnc#1012628).
- HID: alps: Add AUI1657 device ID (bnc#1012628).
- HID: logitech: Add support for Logitech G11 extra keys
  (bnc#1012628).
- HID: multitouch: add eGalaxTouch P80H84 support (bnc#1012628).
- gcc-common.h: Update for GCC 10 (bnc#1012628).
- net: drop_monitor: use IS_REACHABLE() to guard
  net_dm_hw_report() (bnc#1012628).
- kbuild: avoid concurrency issue in parallel building dtbs and
  dtbs_check (bnc#1012628).
- iommu: Fix deferred domain attachment (bnc#1012628).
- mtd: Fix mtd not registered due to nvmem name collision
  (bnc#1012628).
- afs: Don't unlock fetched data pages until the op completes
  successfully (bnc#1012628).
- ubi: Fix seq_file usage in detailed_erase_block_info debugfs
  file (bnc#1012628).
- i2c: mux: demux-pinctrl: Fix an error handling path in
  'i2c_demux_pinctrl_probe()' (bnc#1012628).
- evm: Fix a small race in init_desc() (bnc#1012628).
- iommu/amd: Fix get_acpihid_device_id() (bnc#1012628).
- iommu/amd: Fix over-read of ACPI UID from IVRS table
  (bnc#1012628).
- i2c: fix missing pm_runtime_put_sync in i2c_device_probe
  (bnc#1012628).
- ubifs: remove broken lazytime support (bnc#1012628).
- pipe: Fix pipe_full() test in opipe_prep() (bnc#1012628).
- fix multiplication overflow in copy_fdtable() (bnc#1012628).
- mtd: spinand: Propagate ECC information to the MTD structure
  (bnc#1012628).
- ACPI: EC: PM: Avoid flushing EC work when EC GPE is inactive
  (bnc#1012628).
- ubifs: fix wrong use of crypto_shash_descsize() (bnc#1012628).
- ovl: potential crash in ovl_fid_to_fh() (bnc#1012628).
- ima: Fix return value of ima_write_policy() (bnc#1012628).
- evm: Check also if *tfm is an error pointer in init_desc()
  (bnc#1012628).
- ima: Set file->f_mode instead of file->f_flags in
  ima_calc_file_hash() (bnc#1012628).
- ARC: [plat-hsdk]: fix USB regression (bnc#1012628).
- i2c: dev: Fix the race between the release of i2c_dev and cdev
  (bnc#1012628).
- commit 5afc154
- Update config files.
  Remove ACPI_PROCFS_POWER
  This should all be in sysfs nowadays. If this is in Tumbleweed for a while,
  a patch to totally remove this code will be sent mainline.
  Related to bsc#1160977
- commit 96731f2
- rpm/kernel-source.spec.in: Add obsolete_rebuilds (boo#1172073).
- commit 6524463
- Update to 5.7-rc7
- refresh configs (ARCH_HAS_STRICT_KERNEL_RWX=n on ppc64/ppc64le)
- commit 67f7fb5

==== kernel-source ====
Version update (5.6.14 -> 5.7.1)

- syscalls: fix offset type of ksys_ftruncate (bsc#1172699).
- commit 8d4977c
- armv7/ararch64: Update config files.
  Enable IOMMU_DEFAULT_PASSTHROUGH; per jsc#SLE-5568 this should be on by
  default, like on x86_64.
- commit bb34387
- Refresh
  patches.suse/jbd2-avoid-leaking-transaction-credits-when-unreserv.patch.
  Update upstream status.
- commit c3ae43f
- KVM: x86/mmu: Set mmio_value to '0' if reserved #PF can't be
  generated (bsc#1171904).
- KVM: x86: only do L1TF workaround on affected processors
  (bsc#1171904).
- commit 16721c7
- Linux 5.7.1 (bnc#1012628).
- airo: Fix read overflows sending packets (bnc#1012628).
- net: dsa: mt7530: set CPU port to fallback mode (bnc#1012628).
- media: staging: ipu3-imgu: Move alignment attribute to field
  (bnc#1012628).
- media: Revert "staging: imgu: Address a compiler warning on
  alignment" (bnc#1012628).
- mmc: fix compilation of user API (bnc#1012628).
- kernel/relay.c: handle alloc_percpu returning NULL in relay_open
  (bnc#1012628).
- crypto: api - Fix use-after-free and race in crypto_spawn_alg
  (bnc#1012628).
- mt76: mt76x02u: Add support for newer versions of the XBox
  One wifi adapter (bnc#1012628).
- p54usb: add AirVasT USB stick device-id (bnc#1012628).
- HID: i2c-hid: add Schneider SCL142ALM to descriptor override
  (bnc#1012628).
- HID: multitouch: enable multi-input as a quirk for some devices
  (bnc#1012628).
- HID: sony: Fix for broken buttons on DS3 USB dongles
  (bnc#1012628).
- mm: Fix mremap not considering huge pmd devmap (bnc#1012628).
- media: dvbdev: Fix tuner->demod media controller link
  (bnc#1012628).
- commit cc2f849
- config: refresh with gcc10
  gcc10 is default in Tumbleweed now.
- commit 0b1e86b
- Revert "Update config files."
  This reverts commit 34be040b91701c047e592935bc2dbb46a3947a56. We now
  have a fix (previous commit) in place, so change the configuration back
  (bsc#1156053).
- commit f4546fe
- usercopy: mark dma-kmalloc caches as usercopy caches
  (bsc#1156053).
- commit d3b5ce7
- jbd2: avoid leaking transaction credits when unreserving handle
  (bnc#1169774).
- commit 8599ef4
- jbd2: avoid leaking transaction credits when unreserving handle
  (bnc#1169774).
- Delete
  patches.suse/Revert-ext4-make-dioread_nolock-the-default.patch.
  Replace revert by the upstream fix.
- commit bfa465b
- Refresh
  patches.suse/drm-nouveau-Fix-regression-by-audio-component-transition.patch.
  Update upstream status.
- commit 3000ce5
- config: enable DEBUG_INFO_BTF
  This was disabled when the option was introduced in 5.2-rc1 but it turned
  out there are interesting use cases for having it enabled.
  Add pahole to build time dependencies as it is used to extracth the BTF
  data. Once we figure out how to make it conditional (only if DEBUG_INFO_BTF
  exists and is enabled), it should be done in packaging branch.
- commit 9ddab66
- Updated to 5.7 final
- refresh configs
- commit 7cd0da5
- Update config files.
- commit 6dba057
- Revert "virtio-balloon: Revert "virtio-balloon: Switch back to
  OOM handler for VIRTIO_BALLOON_F_DEFLATE_ON_OOM"" (virtio fix).
- commit fe7831e
- Linux 5.6.15 (bnc#1012628).
- blacklist.conf: remove one entry
- sched/fair: Fix enqueue_task_fair() warning some more
  (bnc#1012628).
- sched/fair: Fix reordering of enqueue/dequeue_task_fair()
  (bnc#1012628).
- sched/fair: Reorder enqueue/dequeue_task_fair path
  (bnc#1012628).
- bpf: Prevent mmap()'ing read-only maps as writable
  (bnc#1012628).
- rxrpc: Fix ack discard (bnc#1012628).
- rxrpc: Trace discarded ACKs (bnc#1012628).
- x86/unwind/orc: Fix unwind_get_return_address_ptr() for inactive
  tasks (bnc#1012628).
- flow_dissector: Drop BPF flow dissector prog ref on netns
  cleanup (bnc#1012628).
- s390/kexec_file: fix initrd location for kdump kernel
  (bnc#1012628).
- tpm: check event log version before reading final events
  (bnc#1012628).
- rxrpc: Fix a memory leak in rxkad_verify_response()
  (bnc#1012628).
- rxrpc: Fix the excessive initial retransmission timeout
  (bnc#1012628).
- iio: imu: st_lsm6dsx: unlock on error in
  st_lsm6dsx_shub_write_raw() (bnc#1012628).
- z3fold: fix use-after-free when freeing handles (bnc#1012628).
- sparc32: fix page table traversal in srmmu_nocache_init()
  (bnc#1012628).
- sparc32: use PUD rather than PGD to get PMD in
  srmmu_nocache_init() (bnc#1012628).
- sh: include linux/time_types.h for sockios (bnc#1012628).
- kasan: disable branch tracing for core runtime (bnc#1012628).
- rapidio: fix an error in get_user_pages_fast() error handling
  (bnc#1012628).
- device-dax: don't leak kernel memory to user space after
  unloading kmem (bnc#1012628).
- s390/kaslr: add support for R_390_JMP_SLOT relocation type
  (bnc#1012628).
- s390/pci: Fix s390_mmio_read/write with MIO (bnc#1012628).
- ipack: tpci200: fix error return code in tpci200_register()
  (bnc#1012628).
- mei: release me_cl object reference (bnc#1012628).
- tty: serial: add missing spin_lock_init for SiFive serial
  console (bnc#1012628).
- misc: rtsx: Add short delay after exit from ASPM (bnc#1012628).
- driver core: Fix handling of SYNC_STATE_ONLY + STATELESS device
  links (bnc#1012628).
- driver core: Fix SYNC_STATE_ONLY device link implementation
  (bnc#1012628).
- iio: adc: ti-ads8344: Fix channel selection (bnc#1012628).
- iio: dac: vf610: Fix an error handling path in
  'vf610_dac_probe()' (bnc#1012628).
- iio: sca3000: Remove an erroneous 'get_device()' (bnc#1012628).
- iio: adc: stm32-dfsdm: fix device used to request dma
  (bnc#1012628).
- iio: adc: stm32-adc: fix device used to request dma
  (bnc#1012628).
- staging: greybus: Fix uninitialized scalar variable
  (bnc#1012628).
- staging: kpc2000: fix error return code in kp2000_pcie_probe()
  (bnc#1012628).
- staging: wfx: unlock on error path (bnc#1012628).
- staging: iio: ad2s1210: Fix SPI reading (bnc#1012628).
- kbuild: Remove debug info from kallsyms linking (bnc#1012628).
- tools/bootconfig: Fix apply_xbc() to return zero on success
  (bnc#1012628).
- Revert "driver core: platform: Initialize dma_parms for platform
  devices" (bnc#1012628).
- virtio-balloon: Revert "virtio-balloon: Switch back to OOM
  handler for VIRTIO_BALLOON_F_DEFLATE_ON_OOM" (bnc#1012628).
- Revert "gfs2: Don't demote a glock until its revokes are
  written" (bnc#1012628).
- drm/i915: Propagate error from completed fences (bnc#1012628).
- drm/i915/gvt: Init DPLL/DDI vreg for virtual display instead
  of inheritance (bnc#1012628).
- vsprintf: don't obfuscate NULL and error pointers (bnc#1012628).
- dmaengine: owl: Use correct lock in owl_dma_get_pchan()
  (bnc#1012628).
- dmaengine: idxd: fix interrupt completion after unmasking
  (bnc#1012628).
- dmaengine: dmatest: Restore default for channel (bnc#1012628).
- drm/etnaviv: Fix a leak in submit_pin_objects() (bnc#1012628).
- dmaengine: tegra210-adma: Fix an error handling path in
  'tegra_adma_probe()' (bnc#1012628).
- apparmor: Fix aa_label refcnt leak in policy_update
  (bnc#1012628).
- apparmor: fix potential label refcnt leak in aa_change_profile
  (bnc#1012628).
- apparmor: Fix use-after-free in aa_audit_rule_init
  (bnc#1012628).
- pinctrl: qcom: Add affinity callbacks to msmgpio IRQ chip
  (bnc#1012628).
- drm/etnaviv: fix perfmon domain interation (bnc#1012628).
- powerpc/64s: Disable STRICT_KERNEL_RWX (bnc#1012628).
- arm64: Fix PTRACE_SYSEMU semantics (bnc#1012628).
- scsi: target: Put lun_ref at end of tmr processing
  (bnc#1012628).
- scsi: qla2xxx: Do not log message when reading port speed via
  sysfs (bnc#1012628).
- ALSA: hda/realtek - Add more fixup entries for Clevo machines
  (bnc#1012628).
- ALSA: hda/realtek - Fix silent output on Gigabyte X570 Aorus
  Xtreme (bnc#1012628).
- ALSA: pcm: fix incorrect hw_base increase (bnc#1012628).
- ALSA: iec1712: Initialize STDSP24 properly when using the
  model=staudio option (bnc#1012628).
- bpf: Add bpf_probe_read_{user, kernel}_str() to
  do_refine_retval_range (bnc#1012628).
- bpf: Restrict bpf_probe_read{, str}() only to archs where they
  work (bnc#1012628).
- Update config files.
- ALSA: hda/realtek: Enable headset mic of ASUS UX581LV with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek - Enable headset mic of ASUS UX550GE with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek - Enable headset mic of ASUS GL503VM with
  ALC295 (bnc#1012628).
- ALSA: hda/realtek: Add quirk for Samsung Notebook (bnc#1012628).
- ALSA: hda/realtek - Add HP new mute led supported for ALC236
  (bnc#1012628).
- ALSA: hda/realtek - Add supported new mute Led for HP
  (bnc#1012628).
- scripts/gdb: repair rb_first() and rb_last() (bnc#1012628).
- tools/bootconfig: Fix resource leak in apply_xbc()
  (bnc#1012628).
- ARM: futex: Address build warning (bnc#1012628).
- KVM: selftests: Fix build for evmcs.h (bnc#1012628).
- drm/amd/display: Prevent dpcd reads with passive dongles
  (bnc#1012628).
- drm/amd/display: fix counter in wait_for_no_pipes_pending
  (bnc#1012628).
- iommu/amd: Call domain_flush_complete() in update_domain()
  (bnc#1012628).
- iommu/amd: Do not loop forever when trying to increase address
  space (bnc#1012628).
- platform/x86: asus-nb-wmi: Do not load on Asus T100TA and T200TA
  (bnc#1012628).
- USB: core: Fix misleading driver bug report (bnc#1012628).
- stmmac: fix pointer check after utilization in stmmac_interrupt
  (bnc#1012628).
- ceph: fix double unlock in handle_cap_export() (bnc#1012628).
- HID: quirks: Add HID_QUIRK_NO_INIT_REPORTS quirk for Dell K12A
  keyboard-dock (bnc#1012628).
- gtp: set NLM_F_MULTI flag in gtp_genl_dump_pdp() (bnc#1012628).
- x86/apic: Move TSC deadline timer debug printk (bnc#1012628).
- selftests: fix kvm relocatable native/cross builds and installs
  (bnc#1012628).
- ftrace/selftest: make unresolved cases cause failure if
  - -fail-unresolved set (bnc#1012628).
- ibmvnic: Skip fatal error reset after passive init
  (bnc#1012628).
- HID: i2c-hid: reset Synaptics SYNA2393 on resume (bnc#1012628).
- scsi: ibmvscsi: Fix WARN_ON during event pool release
  (bnc#1012628).
- net/ena: Fix build warning in ena_xdp_set() (bnc#1012628).
- component: Silence bind error on -EPROBE_DEFER (bnc#1012628).
- aquantia: Fix the media type of AQC100 ethernet controller in
  the driver (bnc#1012628).
- vhost/vsock: fix packet delivery order to monitoring devices
  (bnc#1012628).
- configfs: fix config_item refcnt leak in configfs_rmdir()
  (bnc#1012628).
- scsi: qla2xxx: Delete all sessions before unregister local
  nvme port (bnc#1012628).
- scsi: qla2xxx: Fix hang when issuing nvme disconnect-all in NPIV
  (bnc#1012628).
- HID: alps: ALPS_1657 is too specific; use U1_UNICORN_LEGACY
  instead (bnc#1012628).
- HID: alps: Add AUI1657 device ID (bnc#1012628).
- HID: logitech: Add support for Logitech G11 extra keys
  (bnc#1012628).
- HID: multitouch: add eGalaxTouch P80H84 support (bnc#1012628).
- gcc-common.h: Update for GCC 10 (bnc#1012628).
- net: drop_monitor: use IS_REACHABLE() to guard
  net_dm_hw_report() (bnc#1012628).
- kbuild: avoid concurrency issue in parallel building dtbs and
  dtbs_check (bnc#1012628).
- iommu: Fix deferred domain attachment (bnc#1012628).
- mtd: Fix mtd not registered due to nvmem name collision
  (bnc#1012628).
- afs: Don't unlock fetched data pages until the op completes
  successfully (bnc#1012628).
- ubi: Fix seq_file usage in detailed_erase_block_info debugfs
  file (bnc#1012628).
- i2c: mux: demux-pinctrl: Fix an error handling path in
  'i2c_demux_pinctrl_probe()' (bnc#1012628).
- evm: Fix a small race in init_desc() (bnc#1012628).
- iommu/amd: Fix get_acpihid_device_id() (bnc#1012628).
- iommu/amd: Fix over-read of ACPI UID from IVRS table
  (bnc#1012628).
- i2c: fix missing pm_runtime_put_sync in i2c_device_probe
  (bnc#1012628).
- ubifs: remove broken lazytime support (bnc#1012628).
- pipe: Fix pipe_full() test in opipe_prep() (bnc#1012628).
- fix multiplication overflow in copy_fdtable() (bnc#1012628).
- mtd: spinand: Propagate ECC information to the MTD structure
  (bnc#1012628).
- ACPI: EC: PM: Avoid flushing EC work when EC GPE is inactive
  (bnc#1012628).
- ubifs: fix wrong use of crypto_shash_descsize() (bnc#1012628).
- ovl: potential crash in ovl_fid_to_fh() (bnc#1012628).
- ima: Fix return value of ima_write_policy() (bnc#1012628).
- evm: Check also if *tfm is an error pointer in init_desc()
  (bnc#1012628).
- ima: Set file->f_mode instead of file->f_flags in
  ima_calc_file_hash() (bnc#1012628).
- ARC: [plat-hsdk]: fix USB regression (bnc#1012628).
- i2c: dev: Fix the race between the release of i2c_dev and cdev
  (bnc#1012628).
- commit 5afc154
- Update config files.
  Remove ACPI_PROCFS_POWER
  This should all be in sysfs nowadays. If this is in Tumbleweed for a while,
  a patch to totally remove this code will be sent mainline.
  Related to bsc#1160977
- commit 96731f2
- rpm/kernel-source.spec.in: Add obsolete_rebuilds (boo#1172073).
- commit 6524463
- Update to 5.7-rc7
- refresh configs (ARCH_HAS_STRICT_KERNEL_RWX=n on ppc64/ppc64le)
- commit 67f7fb5

==== konsole ====
Subpackages: konsole-part konsole-part-lang

- Add upstream patches to fix possible crash when closing a session
  in KonsolePart (boo#1169408, kde#420817, kde#420695, kde#415762):
  * Fix-crash-when-closing-session-in-KonsolePart-via-menu.patch
  * Fix-konsolepart-segfault-when-closing-after-showing-context-menu.patch

==== krb5 ====
Version update (1.18.1 -> 1.18.2)
Subpackages: krb5-client

- Update to 1.18.2
  * Fix a SPNEGO regression where an acceptor using the default credential
    would improperly filter mechanisms, causing a negotiation failure.
  * Fix a bug where the KDC would fail to issue tickets if the local krbtgt
    principal's first key has a single-DES enctype.
  * Add stub functions to allow old versions of OpenSSL libcrypto to link
    against libkrb5.
  * Fix a NegoEx bug where the client name and delegated credential might
    not be reported.
- Update logrotate script, call systemd to reload the services
  instead of init-scripts. (boo#1169357)
- Don't add the lto flags to the public link options. (boo#1172038)

==== ksysguard5 ====
Version update (5.19.0 -> 5.19.0.1)
Subpackages: ksysguard5-lang

- Update to 5.19.0.1
  * New bugfix release
- Changes since 5.19.0:
  * Use new name for dbus interface too
  * Don't prefix value output with mount point

==== libgpg-error ====
Version update (1.37 -> 1.38)

- Update to 1.38:
  * New option parser features to implement system wide
    configuration files
  * New functions to build file names
  * New function to help reallocating arrays
  * Protect gpgrt_inc_errorcount against counter overflow
- drop needless autotools build dependencies that were added for
  gawk5.patch

==== libjcat ====
Version update (0.1.2 -> 0.1.2+3)

- Update to version 0.1.2+3:
  * Validate that gpgme_op_verify_result() returned at least one
    signature (CVE-2020-10759).

==== libksysguard5 ====
Version update (5.19.0 -> 5.19.0.1)
Subpackages: libksysguard5-helper libksysguard5-imports libksysguard5-lang

- Update to 5.19.0.1
  * New bugfix release
- Changes since 5.19.0:
  * Use new name for dbus interface

==== libnftnl ====
Version update (1.1.6 -> 1.1.7)

- Update to release 1.1.7
  * udata: add NFTNL_UDATA_SET_DATA_INTERVAL

==== libosinfo ====
Version update (1.7.1 -> 1.8.0)
Subpackages: libosinfo-1_0-0 typelib-1_0-Libosinfo-1_0

- Update to version 1.8.0
  Changes in this release include:
  * Several CI improvements
  * Several release scripts improvements
  * Several translations improvements
  * Several syntax-check improvements
  * Code cleanup in order to modernize the GObject usage
  * Add API to get whether a firmware is supported or not
  * Add API to get "cloud-image-username"

==== libqt5-qtbase ====
Subpackages: libQt5Concurrent5 libQt5Core5 libQt5DBus5 libQt5Gui5 
libQt5Network5 libQt5OpenGL5 libQt5PrintSupport5 libQt5Sql5 libQt5Sql5-mysql 
libQt5Sql5-sqlite libQt5Test5 libQt5Widgets5 libQt5Xml5 
libqt5-qtbase-platformtheme-gtk3

- Add patch to fix tool menu placement (boo#1172754, QTBUG-84462):
  * 0001-Fix-QToolButton-menus-showing-on-primary-screens-in-.patch

==== librsvg ====
Version update (2.48.4 -> 2.48.7)
Subpackages: gdk-pixbuf-loader-rsvg librsvg-2-2 rsvg-thumbnailer 
typelib-1_0-Rsvg-2_0

- Update to version 2.48.7:
  + Fix failing tests.
- Update to version 2.48.6:
  + Fix build on big-endian machines.
- Update to version 2.48.5:
  + Support multiple fonts in the font-family property. Previously
    in font-family="Foo, Bar, Baz" only Foo would get used.
  + Catch overflow when rendering files with a huge viewBox.
  + Don't panic with an empty objectBoundingBox for a mask.
  + Fix introspection data for rsvg_handle_set_stylesheet.
  + Fixes to the librsvg_crate documentation.
  + Loading raster images for inclusion in an SVG and producing
    GdkPixbufs is now faster.

==== libseccomp ====
Version update (2.4.2 -> 2.4.3)

- Update to release 2.4.3
  * Add list of authorized release signatures to README.md
  * Fix multiplexing issue with s390/s390x shm* syscalls
  * Remove the static flag from libseccomp tools compilation
  * Add define for __SNR_ppoll
  * Fix potential memory leak identified by clang in the
    scmp_bpf_sim tool
- Drop no-static.diff, libseccomp-fix_aarch64-test.patch,
  SNR_ppoll.patch (merged)

==== libupnp ====
Subpackages: libixml11 libupnp16

- Add 0001-Fixes-177-NULL-pointer-dereference-in-FindServiceCon.patch
  [boo#1172625]

==== libxml2 ====
Subpackages: libxml2-2 libxml2-tools

- Fix invalid xmlns references since the fix for CVE-2019-19956 [bsc#1172021]
- Revert upstream commit 5a02583c7e683896d84878bd90641d8d9b0d0549
  * Add patch libxml2-CVE-2019-19956.patch

==== libxml2-python ====

- Fix invalid xmlns references since the fix for CVE-2019-19956 [bsc#1172021]
- Revert upstream commit 5a02583c7e683896d84878bd90641d8d9b0d0549
  * Add patch libxml2-CVE-2019-19956.patch

==== libzip ====
Version update (1.6.1 -> 1.7.0)

- libzip 1.7.0:
  * Add support for encrypting using traditional PKWare encryption
  * Add functions for querying supported compression and encryption
    methods
  * Add the ZIP_SOURCE_GET_FILE_ATTRIBUTES` source command
  * Refactor stdio file backend
  * Add CMake find_project() support

==== man-pages ====
Version update (5.06 -> 5.07)

- version update to 5.07
  New and rewritten pages
  - ----------------------
  ioctl_fslabel.2
    New page documenting filesystem get/set label ioctl(2) operations
  Removed pages
  - ------------
  ioctl_list.2
    This page was first added more than 20 years ago. Since
    that time it has seen hardly any update, and is by now
    very much out of date, as reported by Heinrich Schuchardt
    and confirmed by Eugene Syromyatnikov.
  Newly documented interfaces in existing pages
  - --------------------------------------------
  adjtimex.2
    Document clock_adjtime(2)
  clock_getres.2
    Explain dynamic clocks
  clone.2
    Document the clone3() CLONE_INTO_CGROUP flag
  mremap.2
    Document MREMAP_DONTUNMAP
  open.2
    Document fs.protected_fifos and fs.protected_regular
  prctl.2
    Add PR_SPEC_INDIRECT_BRANCH for SPECULATION_CTRL prctls
    Add PR_SPEC_DISABLE_NOEXEC for SPECULATION_CTRL prctls
    Add PR_PAC_RESET_KEYS (arm64)
  ptrace.2
    Document PTRACE_SET_SYSCALL
  proc.5
    Document /proc/sys/fs/protected_regular
    Document /proc/sys/fs/protected_fifos
    Document /proc/sys/fs/aio-max-nr and /proc/sys/fs/aio-nr
- deleted patches
  - man-pages-remove-ioctl_list-reference.patch (upstreamed)

==== mariadb ====
Version update (10.4.12 -> 10.4.13)
Subpackages: libmariadbd19 mariadb-client mariadb-errormessages

- Update _constraints to make it more readable and request
  more memory for aarch64 to avoid occasionnal OOM errors on %check
- rpm macros: $TEST_USER identified by $TEST_PASS is actually user
  of the database for which client conf should be made for
- rpm macros: database name or names can be specified as a
  %mysql_testserver_start and %mysql_testserver_cconf parameter
- modified sources
  % macros.mariadb-test
- Build with oqgraph by default for all codestreams [jsc#SLE-12253]
- Update to 10.4.13
  * release notes and changelog:
    https://mariadb.com/kb/en/library/mariadb-10413-release-notes
    https://mariadb.com/kb/en/library/mariadb-10413-changelog
  * fixes for the following security vulnerabilities:
    CVE-2020-2752, CVE-2020-2812, CVE-2020-2814, CVE-2020-2760,
    CVE-2020-13249
- fixes [bsc#1168380] (the same as [bsc#1166781])
  MDEV-21244 mysql_upgrade creating empty global_priv table support
  upgrades from 5.2 privilege tables
- drop specfile "hacks" as things work correctly in upstream now:
  * renaming tmpfiles.conf -> mariadb.conf
  * installing pam_user_map.so to /lib64/security for non 32bit
    architectures
  * sysusers.conf was renamed to mariadb.conf
- update suse_skipped_tests.list

==== memcached ====
Version update (1.6.5 -> 1.6.6)

- update to 1.6.6:
  * Fix crash on shutdown when handling signals with TLS enabled
  * Disable aarch64 hw crc32 function for now
  * Pull in BigEndian-compatible crc32c
  * minimum libevent version is 2.x

==== mozjs68 ====
Version update (68.7.0 -> 68.9.0)

- Update to version 68.9.0esr:
  * CVE-2020-12399: Timing attack on DSA signatures in NSS library
  * CVE-2020-12405: Use-after-free in SharedWorkerService
  * CVE-2020-12406: JavaScript Type confusion with NativeTypes
  * CVE-2020-12410: Memory safety bugs fixed in Firefox 77 and
    Firefox ESR 68.9
- Changes from version 68.8.0esr:
  * CVE-2020-12387: Use-after-free during worker shutdown
  * CVE-2020-12388: Sandbox escape with improperly guarded Access
    Tokens
  * CVE-2020-12389: Sandbox escape with improperly separated
    process types
  * CVE-2020-6831: Buffer overflow in SCTP chunk input validation
  * CVE-2020-12392: Arbitrary local file access with 'Copy as cURL'
  * CVE-2020-12393: Devtools' 'Copy as cURL' feature did not fully
    escape website-controlled data, potentially leading to command
    injection
  * CVE-2020-12395: Memory safety bugs fixed in Firefox 76 and
    Firefox ESR 68.8
- Drop gcc10-include-fix.patch: Fixed upstream.
- Add Drop_backwards_test-Nuuk.patch: This is now Nuuk in tzdata.

==== multipath-tools ====
Version update (0.8.4+31+suse.8f53764 -> 0.8.4+43+suse.908383f)
Subpackages: kpartx libmpath0

- Update to version 0.8.4+43+suse.908383f:
  * enable negated regular expression syntax in conf file
  * change default devnode blacklist to
    '!^(sd[a-z]|dasd[a-z]|nvme[0-9])'
- Update to version 0.8.4+40+suse.b06c2e5a:
- Fix udev rule processing during coldplug (bsc#1172157)
  * 11-dm-mpath.rules: Fix udev rule processing during coldplug
- Fix compilation with gcc-10
  * fix boolean value with json-c 0.14
  * libmultipath: fix condlog NULL argument in uevent_get_env_var
- Reviewed upstream changes:
  * simplify failed_wwid code
  * centralize path validation code
- Use pkgconfig for BuildRequires

==== ncurses ====
Version update (6.2.20200502 -> 6.2.20200531)
Subpackages: libncurses6 ncurses-devel ncurses-utils tack terminfo 
terminfo-base terminfo-iterm terminfo-screen

- Add ncurses patch 20200531
  + correct configure version-check/warnng for g++ to allow for 10.x
  + re-enable "bel" in konsole-base (report by Nia Huang)
  + add linux-s entry (patch by Alexandre Montaron).
  + drop long-obsolete convert_configure.pl
  + add test/test_parm.c, for checking tparm changes.
  + improve parameter-checking for tparm, adding function _nc_tiparm() to
    handle the most-used case, which accepts only numeric parameters
    (report/testcase by "puppet-meteor").
  + use a more conservative estimate of the buffer-size in lib_tparm.c's
    save_text() and save_number(), in case the sprintf() function
    passes-through unexpected characters from a format specifier
    (report/testcase by "puppet-meteor").
  + add a check for end-of-string in cvtchar to handle a malformed
    string in infotocap (report/testcase by "puppet-meteor").
- Add ncurses patch 20200523
  + update version-check for gnat to allow for gnat 10.x to 99.x
  + fix an uninitialized variable in lib_mouse.c changes (cf: 20200502)
  + add a check in EmitRange to guard against repeat_char emitting digits
    which could be interpreted as BSD-style padding when --enable-bsdpad
    is configured (report/patch by Hiltjo Posthuma).
  + add --disable-pkg-ldflags to suppress EXTRA_LDFLAGS from the
    generated pkg-config and ncurses*-config files, to simplify
    configuring in the case where rpath is used but the packager wants
    to hide the feature (report by Michael Stapelberg).
  > fixes for building with Visual Studio C++ and msys2 (patches by
    "Maarten Anonymous"):
  + modify CF_SHARED_OPTS to generate a script which translates linker
    options into Visual Studio's dialect.
  + omit parentheses around function-names in generated lib_gen.c to
- Add ncurses patch 20200516
  + add notes on termcap.h header in curs_termcap.3x
  + update notes on vscode / xterm.js -TD
- Add ncurses patch 20200509
  + add "-r" option to the dots test-programs, to help with scripting
    a performance comparison.
  + build-fix test/move_field.c for NetBSD curses, whose form headers
    use different names than SVr4 or ncurses.

==== newt ====

- Split doc build into separate spec file
- As the example scripts are "pointless", just don't install them

==== nfs-utils ====
Subpackages: libnfsidmap1 nfs-client nfs-doc nfs-kernel-server

- Remove README.NFSv4.  It is out dated and not useful.  All
  the configation described is now done automatically.
  (bsc#1171448)

==== nftables ====
Version update (0.9.4 -> 0.9.5)
Subpackages: libnftables1

- Update to release 0.9.5
  * Support for set counters.
  * Support for restoring set element counters via nft -f.
  * Counter support for flowtables.
  * typeof concatenations support for sets.
  * Support for concatenated ranges in anonymous sets.
  * Allow to reject packets with 802.1q from the bridge family.
  * Support for matching on the conntrack ID.
- Drop anonset-crashfix.patch (upstream solved differently)

==== nodejs-common ====
Version update (3.0 -> 4.0)

- Add nodejs-default, npm-default and nodejs-devel-default subpackages
  to provide latest, best supported nodejs for current architecture
  and codestream.
  nodejs-default       - nodejs runtime only
  npm-default          - if you need npm + nodejs
  nodejs-devel-default - if you need npm + nodejs + compile modules

==== open-iscsi ====
Subpackages: iscsiuio libopeniscsiusr0_2_0

- Merged in latest upstream. Summary:
  * Let initiator name be created by iscsi-init.service.
  * iscsi: fix fd leak
  * iscsi: Add break to while loop
  * Fix compiler complaint about string copy in iscsiuio
  * Fix a compiler complaint about writing one byte
  * Fix issue with zero-length arrays at end of struct
  * Add iscsi-init.service
  * Proper disconnect of TCP connection
  * Fix SIGPIPE loop in signal handler
  * Update iscsi-iname.c
  * log:modify iSCSI shared memory permissions for logs
  * Ignore iface.example in iface match checks
  * More changes for musl.
  * Fix type mismatch under musl.
  * Change include of <sys/poll.h> to <poll.h>
  * iscsi-iname: fix iscsi-iname -p access NULL pointer without given IQN prefix
  Note that the "Add iscsi-init.service" change adds a new systemd
  service called "iscsi-init", that creates the iSCSI initiator name
  file /etc/iscsi/initiatorname.iscsi, if and only if it does not
  exist. This obviates the need to do this from the SPEC file, now
  updated.
  Since this was not a version-number update, in addition to modifying
  the SPEC file, also updates:
  * open-iscsi-SUSE-latest.diff.bz2

==== openssh ====
Version update (8.1p1 -> 8.3p1)
Subpackages: openssh-helpers

- Version update to 8.3p1:
  = Potentially-incompatible changes
  * sftp(1): reject an argument of "-1" in the same way as ssh(1) and
    scp(1) do instead of accepting and silently ignoring it.
  = New features
  * sshd(8): make IgnoreRhosts a tri-state option: "yes" to ignore
    rhosts/shosts, "no" allow rhosts/shosts or (new) "shosts-only"
    to allow .shosts files but not .rhosts.
  * sshd(8): allow the IgnoreRhosts directive to appear anywhere in a
    sshd_config, not just before any Match blocks.
  * ssh(1): add %TOKEN percent expansion for the LocalFoward and
    RemoteForward keywords when used for Unix domain socket forwarding.
  * all: allow loading public keys from the unencrypted envelope of a
    private key file if no corresponding public key file is present.
  * ssh(1), sshd(8): prefer to use chacha20 from libcrypto where
    possible instead of the (slower) portable C implementation included
    in OpenSSH.
  * ssh-keygen(1): add ability to dump the contents of a binary key
    revocation list via "ssh-keygen -lQf /path".
- Additional changes from 8.2p1 release:
  = Potentially-incompatible changes
  * ssh(1), sshd(8), ssh-keygen(1): this release removes the "ssh-rsa"
    (RSA/SHA1) algorithm from those accepted for certificate signatures
    (i.e. the client and server CASignatureAlgorithms option) and will
    use the rsa-sha2-512 signature algorithm by default when the
    ssh-keygen(1) CA signs new certificates.
  * ssh(1), sshd(8): this release removes diffie-hellman-group14-sha1
    from the default key exchange proposal for both the client and
    server.
  * ssh-keygen(1): the command-line options related to the generation
    and screening of safe prime numbers used by the
    diffie-hellman-group-exchange-* key exchange algorithms have
    changed. Most options have been folded under the -O flag.
  * sshd(8): the sshd listener process title visible to ps(1) has
    changed to include information about the number of connections that
    are currently attempting authentication and the limits configured
    by MaxStartups.
  * ssh-sk-helper(8): this is a new binary. It is used by the FIDO/U2F
    support to provide address-space isolation for token middleware
    libraries (including the internal one). It needs to be installed
    in the expected path, typically under /usr/libexec or similar.
  = New features
  * This release adds support for FIDO/U2F hardware authenticators to
    OpenSSH. U2F/FIDO are open standards for inexpensive two-factor
    authentication hardware that are widely used for website
    authentication.  In OpenSSH FIDO devices are supported by new public
    key types "ecdsa-sk" and "ed25519-sk", along with corresponding
    certificate types.
  * sshd(8): add an Include sshd_config keyword that allows including
    additional configuration files via glob(3) patterns.
  * ssh(1)/sshd(8): make the LE (low effort) DSCP code point available
    via the IPQoS directive.
  * ssh(1): when AddKeysToAgent=yes is set and the key contains no
    comment, add the key to the agent with the key's path as the
    comment.
  * ssh-keygen(1), ssh-agent(1): expose PKCS#11 key labels and X.509
    subjects as key comments, rather than simply listing the PKCS#11
    provider library path.
  * ssh-keygen(1): allow PEM export of DSA and ECDSA keys.
  * ssh(1), sshd(8): make zlib compile-time optional, available via the
    Makefile.inc ZLIB flag on OpenBSD or via the --with-zlib configure
    option for OpenSSH portable.
  * sshd(8): when clients get denied by MaxStartups, send a
    notification prior to the SSH2 protocol banner according to
    RFC4253 section 4.2.
  * ssh(1), ssh-agent(1): when invoking the $SSH_ASKPASS prompt
    program, pass a hint to the program to describe the type of
    desired prompt.  The possible values are "confirm" (indicating
    that a yes/no confirmation dialog with no text entry should be
    shown), "none" (to indicate an informational message only), or
    blank for the original ssh-askpass behaviour of requesting a
    password/phrase.
  * ssh(1): allow forwarding a different agent socket to the path
    specified by $SSH_AUTH_SOCK, by extending the existing ForwardAgent
    option to accepting an explicit path or the name of an environment
    variable in addition to yes/no.
  * ssh-keygen(1): add a new signature operations "find-principals" to
    look up the principal associated with a signature from an allowed-
    signers file.
  * sshd(8): expose the number of currently-authenticating connections
    along with the MaxStartups limit in the process title visible to
    "ps".
- Rebased patches:
  * openssh-7.7p1-cavstest-ctr.patch
  * openssh-7.7p1-cavstest-kdf.patch
  * openssh-7.7p1-fips.patch
  * openssh-7.7p1-fips_checks.patch
  * openssh-7.7p1-ldap.patch
  * openssh-7.7p1-no_fork-no_pid_file.patch
  * openssh-7.7p1-sftp_print_diagnostic_messages.patch
  * openssh-8.0p1-gssapi-keyex.patch
  * openssh-8.1p1-audit.patch
  * openssh-8.1p1-seccomp-clock_nanosleep.patch
- Removed openssh-7.7p1-seed-prng.patch (bsc#1165158).

==== osinfo-db ====
Version update (20200214 -> 20200529)

- Update database to version 20200529
- Drop 5bbe30db-opensuse-add-info-about-UEFI-support.patch

==== package-update-indicator ====

- Adding patch 
org.guido-berhoerster.code.package-update-indicator.desktop.in.patch
  fixing package-update-indicator should not start within
  Gnome or KDE (boo#1172623)

==== patterns-base ====
Subpackages: patterns-base-apparmor patterns-base-base patterns-base-basesystem 
patterns-base-basic_desktop patterns-base-console patterns-base-documentation 
patterns-base-enhanced_base patterns-base-minimal_base 
patterns-base-sw_management patterns-base-transactional_base patterns-base-x11 
patterns-base-x11_enhanced

- Suggest postfix from the basesystem pattern: suggested packages
  are not flagged for installation, but give the solver a hint. So
  in case something wants an MTA (smtp_daemon), openSUSE installs
  will all default to postfix (as the base pattern is generally
  installed). Users are still free to switch as they wish
  (boo#1136078).

==== perl ====
Subpackages: perl-base perl-doc

- Fixes for %_libexecdir changing to /usr/libexec

==== perl-CGI ====
Version update (4.48 -> 4.49)

- updated to 4.49
  see /usr/share/doc/packages/perl-CGI/Changes
  4.49 2020-06-08
    [ FIX ]
  - remove deprecation warning as no longer in core (GH #221)

==== perl-Date-Manip ====
Version update (6.81 -> 6.82)

updated to 6.82
  see /usr/share/doc/packages/perl-Date-Manip/Changes
  6.82  2020-06-01
  - Time zone fixes
    Newest zoneinfo data (tzdata 2020a).

==== perl-Mojolicious ====
Version update (8.52 -> 8.53)

- updated to 8.53
  see /usr/share/doc/packages/perl-Mojolicious/Changes
  8.53  2020-06-09
  - Added EXPERIMENTAL extname method to Mojo::File.
  - Fixed a bug in Mojolicious::Types where dotfiles would be considered file 
extensions.

==== perl-libwww-perl ====
Version update (6.44 -> 6.45)

- updated to 6.45
  see /usr/share/doc/packages/perl-libwww-perl/Changes
  6.45      2020-06-08 14:51:28Z
  - Fix Client-Warning: Internal response sometimes reset (GH#341) (Jonathan
    Dahan and Julien Fiegehenn)

==== permissions ====
Version update (1550_20200520 -> 1550_20200526)
Subpackages: chkstat permissions-config permissions-doc

- Update to version 20200526:
  * profiles: add entries for enlightenment (bsc#1171686)

==== pidgin ====
Version update (2.13.0 -> 2.14.0)
Subpackages: libpurple libpurple-tcl

- Update to version 2.14.0:
  + General:
  * Fixed a memory leak in search results (pidgin.im#17292).
  * Support SNI with GnuTLS (pidgin.im#17300 tiagosalem).
  * Add additional error handling to NSS and GnuTLS.
  + libpurple:
  * Add invisible buddy support to support presence/name/photos
    for non-buddies (pidgin.im#17295).
  * Make purple-remote compatible with both Python 2 and Python 3.
  * Fix some leaky deprecation warnings.
  * Fix HTML logs which were writing invalid HTML
    (pidgin.im#17280).
  * Fix use after free in purple_smiley_set_data_impl.
  * Added the chat_send_file ability to protocol plugins.
  + Pidgin:
  * Treat <p> tags as line breaks when pasting.
  * Reverted pidgin.im#17232.
    It caused more harm than good.
  + Bonjour:
  * Always use port fallback for IPv4 addresses.
  + XMPP:
  * Support for XEP-0198 Stream Management.
  * Decrease delay for file transfer using streamhosts.
  + Voice & Video:
  * Improve webcam failure handling.
  * Show error when creating media pipeline fails.
  * Clip audio level reporting (pidgin.im#14426).
  * Keep track of devices managed by GstDeviceMonitor.
  * Ignore PulseAudio monitors.
  * Backport native Voice & Video prefs from 3.0.
  * Fix building against GStreamer 0.10.
  * Fix initial delay on incoming audio.
  * Properly cleanup timeouts.
  * Add an audio mixer so mixed sources don't cause a pipe
    failure.
  * Add screen share support for Wayland via XDP Portal.
  * Handle unplug and replug events of selected media device.
- Rebase pidgin-nonblock-common.patch.
- Drop pidgin-enable-sni-gnutls.patch,
  pidgin-Leaky-deprecation-clean-ups.patch: fixed upstream.
- Drop pidgin-ncurses-6.0-accessors.patch: moved to the libgnt
  package.
- Drop support for openSUSE older than Leap 15.0.

==== postgresql ====
Subpackages: postgresql-contrib postgresql-llvmjit postgresql-server

- Disable LLVM on SLE (bsc#1172274).
- Conflict with versions of the binary packages prior to the
  May 2020 update, because we changed the package layout at that
  point and need a clean cutover.

==== postgresql12 ====
Version update (12.2 -> 12.3)
Subpackages: libpq5 postgresql12-contrib postgresql12-llvmjit 
postgresql12-server

- update to 12.3 (bsc#1171924).
  https://www.postgresql.org/about/news/2038/
  https://www.postgresql.org/docs/12/release-12-3.html
- Unify the spec file to work across all current PostgreSQL
  versions to simplify future maintenance.
- Move from the "libs" build flavour to a "mini" package that will
  only be used inside the build service and not get shipped, to
  avoid confusion with the debuginfo packages (bsc#1148643).
- update to 12.3
  https://www.postgresql.org/about/news/2038/
  https://www.postgresql.org/docs/12/release-12-3.html
- Temporarily disable JIT support on SLE until support status of
  clang has been clarified.
- We only need clang for LLVM, not clang-devel.

==== powertop ====
Version update (2.12 -> 2.13)

- Update to 2.13:
  * Update README.md
  * configure.ac: use ax_cxx_compile_stdcxx instead
  * po: regenerate gettext files
  * Enable support for DNV
  * intel_cpus: Fix ICX definition
  * configure.ac: add missing checks from autoscan
  * gettext: update to 0.20.2
  * remove INSTALL relic
  * Doxyfile.in: refresh for version 1.8.18
  * Doxyfile.in: modernize configuration
  * intel_cpus: Fix SKY-X definition
  * Dropped unused variable "entry" detected by Coverity
  * intel_cpus.cpp: Only call closedir() if opened
- Add BuildRequires for autoconf, autoconf-archive, automake, libtool
  because each release they forget to create a release tarball
  until I ping them

==== pulseaudio ====
Subpackages: libpulse-mainloop-glib0 libpulse0 pulseaudio-bash-completion 
pulseaudio-gdm-hooks pulseaudio-module-bluetooth pulseaudio-module-gsettings 
pulseaudio-module-x11 pulseaudio-module-zeroconf pulseaudio-utils 
pulseaudio-zsh-completion

- for libpulse-devel-32bit, require libpulse0-32bit + 
libpulse-mainloop-glib0-32bit
  to help wine development (bsc#1172301)

==== purge-kernels-service ====

- Add split provides for upgrade from old dracut (boo#1168727).

==== python ====

- Add patch configure_PYTHON_FOR_REGEN.patch which makes
  configure.ac to consider the correct version of
  PYTHON_FO_REGEN (bsc#1078326).

==== python-base ====
Subpackages: libpython2_7-1_0

- Add patch configure_PYTHON_FOR_REGEN.patch which makes
  configure.ac to consider the correct version of
  PYTHON_FO_REGEN (bsc#1078326).

==== python-greenlet ====
Version update (0.4.15 -> 0.4.16)

- update to 0.4.16:
  - Support for DEC Alpha architecture
  - Support for Python 3.9
  - Support for Python 3.10a0

==== python-passlib ====

- replace nose with pytest

==== python-ptyprocess ====

- replace nose with unittest

==== python-rpm-macros ====
Version update (20200207.5feb6c1 -> 20200529.b301e36)
Subpackages: python-rpm-generators

- Update to version 20200529.b301e36:
  * update-alternatives are quiet during install

==== python3 ====
Subpackages: python3-curses python3-dbm

- add requires python3-base on libpython subpackage (bsc#1167008)
- build against Sphinx 2.x until python is compatible with
  Sphinx 3.x (see gh#python/cpython#19397, bpo#40204)
- Fix build with SQLite 3.32 (bpo#40783)
  add bpo40784-Fix-sqlite3-deterministic-test.patch

==== python3-base ====
Subpackages: libpython3_8-1_0

- add requires python3-base on libpython subpackage (bsc#1167008)
- build against Sphinx 2.x until python is compatible with
  Sphinx 3.x (see gh#python/cpython#19397, bpo#40204)
- Fix build with SQLite 3.32 (bpo#40783)
  add bpo40784-Fix-sqlite3-deterministic-test.patch

==== redis ====
Version update (6.0.4 -> 6.0.5)

- redis 6.0.5:
  * Fix handling of speical chars in ACL LOAD
  * Make Redis Cluster more robust about operation errors that may
    lead to two clusters to mix together
  * Revert the sendfile() implementation of RDB transfer
  * Fix TLS certificate loading for chained certificates
  * Fix AOF rewirting of KEEPTTL SET option
  * Fix MULTI/EXEC behavior during -BUSY script errors

==== remmina ====
Version update (1.4.5 -> 1.4.6)
Subpackages: remmina-lang remmina-plugin-rdp remmina-plugin-secret 
remmina-plugin-vnc remmina-plugin-xdmcp

- Update to release 1.4.6
  * Hotkey language fixed
  * Fetch news from remmina.org optional
  * allow saving notes in connection profile
  * RDP: Improving hardware option parsing
  * Rearranged widgets in a new Behavior tab
  * Add separator only when there are saved profiles. Fixes #1914
  * Implementing resume all for FTP file transfer, should fix #2210
  * Edit or connect using multiple profile files from the command line
  * Desktop session files for Remmina kiosk are optional
  * Spelling fixes
  * Translation fixes/improvements
  * Feat/lebowski
- Disabled news
- Enabled kiosk sessions

==== rubygem-nokogiri ====
Subpackages: ruby2.6-rubygem-nokogiri ruby2.7-rubygem-nokogiri

- add fix so we no longer need mini_portile2. This is only needed
  when not building against system libraries (boo#1171881)
  https://github.com/sparklemotion/nokogiri/issues/2033

==== schily ====
Subpackages: cdda2wav cdrecord libcdrdeflt1_0 libdeflt1_0 libedc_ecc1_0 
libedc_ecc_dec1_0 libfile1_0 libfind4_0 libparanoia1_0 librmt1_0 librscg1_0 
libscg1_0 libscgcmd1_0 libschily2_0 mkisofs readcd spax star

- Update to release 2020.06.09
  * star: A new option -one-file has been added that causes star
    to exit after a single file has been extracted as a result
    from a pattern match or command line argument match.
  * star: A new option iskip=# has been introduced. The argument
    is the number of bytes to skip before looking for the first
    archive header in the first tape block read after star
    started.
  * star: A new option mtskip=# has been introduced. This option
    causes star to issue a "mt fsr xxx" equivalent on a tape
    archive.

==== shadow ====

- Use pure #!/bin/sh in:
  * useradd.local
  * userdel-post.local
  * userdel-pre.local

==== sqlite3 ====
Version update (3.31.1 -> 3.32.2)

- SQLite 3.32.2:
  * Fix a long-standing bug in the byte-code engine that can cause
    a COMMIT command report as success when in fact it failed to commit
- SQLite 3.32.1:
  * CVE-2020-13435: Malicious SQL statements could have crashed the
    process that is running SQLite (boo#1172091)
- SQLite 3.32.0:
  * Add support for approximate ANALYZE using the PRAGMA
    analysis_limit command
  * Add the bytecode virtual table
  * Add the checksum VFS shim to the set of run-time loadable
    extensions included in the source tree
  * Add the iif() SQL function.
  * INSERT and UPDATE statements now always apply column affinity
    before computing CHECK constraints
  * Increase the default upper bound on the number of parameters
    from 999 to 32766
  * Add code for the UINT collating sequence as an optional
    loadable extension
  * multiple enhancements to the CLI
- drop upstreamed patches:
  * 04885763c4cd00cb-s390-compatibility.patch
  * b20503aaf5b6595a-adapt-FTS-tests-for-big-endian.patch

==== sssd ====
Version update (2.2.3 -> 2.3.0)
Subpackages: libsss_certmap0 libsss_idmap0 libsss_nss_idmap0 sssd-krb5-common 
sssd-ldap

- Update to release 2.3.0
  * SSSD can now handle hosts and networks nsswitch databases
    (see resolve_provider option).
  * By default, authentication request only refresh user's
    initgroups if it is expired or there is not active user's
    session (see pam_initgroups_scheme option).
  * OpenSSL is used as default crypto provider, NSS is deprecated.
  * The AD provider now defaults to GSS-SPNEGO SASL mechanism
    (see ldap_sasl_mech option).
  * The AD provider can now be configured to use only ldaps port
    (see ad_use_ldaps option).
  * SSSD now accepts host entries from GPO's security filter.
  * New debug level (0x10000) added for low level LDB messages
    only (see sssd.conf man page).
- Drop sssd-gpo_host_security_filter-2.2.2.patch,
  0001-Resolve-computer-lookup-failure-when-sam-cn.patch,
  0001-AD-use-getaddrinfo-with-AI_CANONNAME-to-find-the-FQD.patch (merged)
- Drop 0001-Fix-build-failure-against-samba-4.12.0rc1.patch
  (unapplicable)

==== strace ====
Version update (5.6 -> 5.7)

- Update to strace 5.7
  * Improvements
  * Implemented interval specification in "when=" subexpression of syscall
    tampering expressions.
  * Added -e trace=%clock option for tracing syscalls reading of modifying
    system clocks.
  * Implemented decoding of BPF_LINK_CREATE and BPF_LINK_UPDATE bpf
    syscall commands.
  * Updated decoding of clone3 syscall to match Linux 5.7.
  * Updated lists of BPF_*, BTRFS_*, CLONE_*, FAN_*, IORING_*, KVM_*,
    LWTUNNEL_*, MREMAP_*, PERF_*, SECCOMP_*, UFFDIO_*, V4L2_*, and XDP_*
    constants.
  * Updated lists of ioctl commands from Linux 5.7.
  * Bug fixes
  * Fixed decoding of getdents and getdents64 syscalls when they return
    a lot of directory entries.
  * Fixed pathtrace matching of openat2 syscall.

==== suse-module-tools ====
Version update (15.3.2 -> 15.3.3)

- Reverted back to tar_scm source service
  (obs_scm doesn't work well for Ring0 packages)
- Update to version 15.3.3:
  * spec: remove SLE/openSUSE difference in allow_unsupported_modules
  (jsc#SLE-12255)
  * spec: use same fs_blacklist on SLE and openSUSE
  (jsc#SLE-12255, jsc#SLE-3926)
  * spec: use br_netfilter softdep only for SLE12
  (jsc#SLE-12255, bsc#1166531, boo#1158817, bsc#937216)

==== systemd ====
Subpackages: libsystemd0 libudev-devel libudev1 systemd-container systemd-doc 
systemd-logger systemd-sysvinit udev

- Import commit a6d31d1a02c2718a064bbbc40d003668acf72769
  bb6e2f7906 pid1: update manager settings on reload too (bsc#1163109)
  e9e8907b06 watchdog: reduce watchdog pings in timeout interval
  385a8f9846 udev: rename the persistent link for ATA devices (bsc#1164538)
  66018a12ae tmpfiles: remove unnecessary assert (bsc#1171145)
- Disable bump of /proc/sys/fs/nr-open
  Hopefully a _temporary_ workaround until bsc#1165351 is fixed
  otherwise user instances crashes the system is using NIS (and the
  nscd cache is empty).

==== texlive ====
Subpackages: libkpathsea6 libsynctex2

- Properly configure luajit

==== timezone ====

- timezone modifies a file below /usr/share (boo#1172521)
- zdump --version reported "unknown" (boo#1172055)

==== timezone-java ====

- timezone modifies a file below /usr/share (boo#1172521)
- zdump --version reported "unknown" (boo#1172055)

==== uchardet ====
Version update (0.0.6 -> 0.0.7)

- Update to version 0.0.7
  * New supports:
    + Croatian - ISO-8859-2, ISO-8859-13, ISO-8859-16, IBM852,
    Windows-1250 and MAC-CENTRALEUROPE
    + Czech - Windows-1250, ISO-8859-2, IBM852 and
    Mac-CentralEurope.
    + Estonian - ISO-8859-4, ISO-8859-13, ISO-8859-13,
    Windows-1252 and Windows-1257.
    + Finnish - ISO-8859-1, ISO-8859-4, ISO-8859-9, ISO-8859-13,
    ISO-8859-15 and WINDOWS-1252.
    + Irish Gaelic - ISO-8859-1, ISO-8859-9, ISO-8859-15 and
    WINDOWS-1252.
    + Italian - ISO-8859-1, ISO-8859-3, ISO-8859-9, ISO-8859-15
    and WINDOWS-1252.
    + Latvian - ISO-8859-4, ISO-8859-10 and ISO-8859-13
    + Lithuanian - ISO-8859-4, IISO-8859-10 and SO-8859-13
    + Maltese - ISO-8859-3.
    + Polish - ISO-8859-2, ISO-8859-13, ISO-8859-16,
    Windows-1250, IBM852, MAC-CENTRALEUROPE.
    + Portuguese - ISO-8859-1, ISO-8859-9, ISO-8859-15 and
    Windows-1252.
    + Romanian - ISO-8859-2, ISO-8859-16, Windows-1250 and
    IBM852.
    + Slovak - Windows-1250, ISO-8859-2, IBM852 and
    Mac-CentralEurope.
    + Slovene - ISO-8859-2, ISO-8859-16, Windows-1250, IBM852
    and MAC-CENTRALEUROPE.
    + Swedish - ISO-8859-1, ISO-8859-4, ISO-8859-9, ISO-8859-15
    and WINDOWS-1252.
  * EUC-KR now returned as UHC: despite differences, mostly
    upward compatible. Let's return UHC until separate detection
    machines are implemented.
  * uchardet CLI tool now supports the end-of-options -- option
    to be able to process any file starting with a dash.
  * uchardet_handle_data() API considers an empty string input
    as successful processing to improve automatic detection from
    random input sources.
  * Repository code now requires C++1 standard.
  * Several bugs fixed.

==== util-linux ====
Subpackages: libblkid-devel libblkid1 libfdisk1 libmount1 libsmartcols1 
libuuid-devel libuuid1

- Add patch to fix sfdisk not reading its own scripts:
  * libfdisk-script-accept-sector-size.patch
- Use %autopatch
- Fix verification of mount, su and umount (bsc#1166948)

==== util-linux-systemd ====

- Add patch to fix sfdisk not reading its own scripts:
  * libfdisk-script-accept-sector-size.patch
- Use %autopatch
- Fix verification of mount, su and umount (bsc#1166948)

==== vim ====
Subpackages: gvim vim-data vim-data-common

- remove duplicated settings in defaults.vim from SUSE vimrc
- move SUSE vim settings to /usr in data-common package so leave
  /etc/vimrc to the admin.
- require data-common in vim-small so it gets the settings
- install spec file template as plugin as vim-small doesn't support
  it

==== wireless-regdb ====

- Fixes for %_libexecdir changing to /usr/libexec

==== wireshark ====
Subpackages: libwireshark13 libwiretap10 libwsutil11 wireshark-ui-qt

- Add _constraints for ppc/ppc64le that need more than 3GB to build

==== xdg-utils ====
Version update (1.1.3+20190413 -> 1.1.3+20200220)

- Update to version 1.1.3+20200220:
  * fixed #166: xdg-open dose not search correctly in directories with spaces 
in the name

==== xdm ====
Subpackages: xdm-xsession

- Fixes for %_libexecdir changing to /usr/libexec

==== xf86-input-wacom ====

- U_Change-default-gesture-mode-touchpad-on-touchscreen-.patch
  * disable gesture mode on Touchscreens by default (boo#1172669)

==== xterm ====
Subpackages: xterm-bin

- Fixes for %_libexecdir changing to /usr/libexec

==== yast2 ====
Version update (4.3.5 -> 4.3.6)
Subpackages: yast2-logs

- Fix Xen detection (bsc#1172742).
- 4.3.6

==== yast2-add-on ====
Version update (4.3.0 -> 4.3.1)

- Reduce autoyast profile size if addons are empty (bsc#1172749)
- 4.3.1

==== yast2-bootloader ====
Version update (4.3.3 -> 4.3.5)

- AutoYaST: import AutoInstall only when needed (related to
  bsc#1171335).
- 4.3.5
- AutoYaST: Cleanup/improve issue handling (bsc#1171335).
- 4.3.4

==== yast2-installation ====
Version update (4.3.1 -> 4.3.2)

- Fixed yupdate script to correctly install the needed Ruby gems
  (bsc#1172793)
- 4.3.2

==== yast2-kdump ====
Version update (4.3.0 -> 4.3.1)

- Reduce autoyast profile size if kdump is disabled (bsc#1172749)
- 4.3.1

==== yast2-proxy ====
Version update (4.3.0 -> 4.3.1)

- Reduce autoyast profile size if proxy is disabled (bsc#1172749)
- 4.3.1


-- 
To unsubscribe, e-mail: opensuse-arm+unsubscr...@opensuse.org
To contact the owner, e-mail: opensuse-arm+ow...@opensuse.org

Reply via email to